SCHNEIER

Urban VPN Proxy Surreptitiously Intercepts AI Chats_SCHNEIER:296B983F93CF28DFEBC19141CE0D134E

Description

This is pretty scary:

> Urban VPN Proxy targets conversations across ten AI platforms: ChatGPT, Claude, Gemini, Microsoft Copilot, Perplexity, DeepSeek, Grok (xAI), Meta AI.
>
> For each platform, the extension includes a dedicated "executor" script designed to intercept and capture conversations. The harvesting is enabled by default through hardcoded flags in the extension's configuration.
>
> There is no user-facing toggle to disable this. The only way to stop the data collection is to uninstall the extension entirely.
>
> […]
>
> The data collection operates independently of the VPN functionality. Whether the VPN is connected or not, the harvesting runs continuously in the background.
>
> […]
>
> What gets captured:
>
> * Every prompt you send to the AI
> Every response you receive
>
> * Conversation identifiers and timestamps
> * Session metadata
> * The specific AI platform and model used

Boing Boing post.
Visit Original Source

Basic Information

ID SCHNEIER:296B983F93CF28DFEBC19141CE0D134E
Published Dec 24, 2025 at 12:03
Modified Dec 23, 2025 at 17:07

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.