[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"news-slug-openai-obi-cookie-cross-site-tracking":3,"topics-all":38,"news-related-ea6de12d-e8bf-4013-a299-14211805ba30":57},{"id":4,"title":5,"summary":6,"content":7,"original_url":8,"source_id":9,"tags":10,"translations":24,"news_slug":31,"published_at":32,"created_at":33,"modified_at":34,"is_published":35,"publish_type":36,"image_url":14,"view_count":37},"ea6de12d-e8bf-4013-a299-14211805ba30","ChatGPT __obi cookie 把你带到站外:1 年同站标识","独立研究 9 月 20 日披露,ChatGPT 写入一个 1 年期 cookie __obi,作用域 .openai.com,是 OpenAI 策略中唯一配置为可跨站携带的标识。在 Chewy、Wayfair、Eventbrite 等商家站点验证它会随广告 SDK 被回传。","过去几周 AI 隐私领域最扎眼的一篇独立披露,既不是漏洞利用,也不是 P0 级别的安全事件,而是一个被白纸黑字写在 OpenAI 自家 cookie 策略里的、配置成「跨站可携带」的 cookie:__obi。\n\n## 9 月 20 日的披露\n\n独立安全研究者 Jamie Larson 9 月 20 日在 Buchodi Threat Intel 公开了一篇长文,描述 OpenAI 在 bzr.openai.com 上的广告收集器会写入一个名为 __obi 的 cookie,作用域为 .openai.com,有效期 1 年,配置为 SameSite=None;Secure。这正是浏览器允许跨站请求带出 cookie 的唯一组合,而 OpenAI 自己的 cookie 策略里所有其他标识都配置了 SameSite=Lax 或受域限制,被浏览器默认阻断。\n\n研究者在自己手机上复现了完整链路,并用两种独立抓包方法交叉验证,样本覆盖 936 个广告像素、1029 个域名、共 23929 次请求。当用户随后访问安装了 OpenAI 广告 SDK 的商家网站时,这个 cookie 会随像素请求一起被发回 OpenAI 的广告基础设施。OpenAI 可将用户在这些网站上的浏览行为——搜索的产品、阅读的文章、购买的动作——映射回 ChatGPT 账户。\n\n## 三个步骤拆解\n\n第一步,客户端在 chatgpt.com 上生成 16 字节随机数,调用 \u002Fbackend-api\u002Fbazaar\u002Fobi\u002Fsync-token,后端返回 RS256 JWT,内含账号 sub 字段和 obi 字段,有效期 60 秒。iss 为 chatgpt-wadi,aud 为 bzr.openai.com,bzr 是 OpenAI 内部对广告平台的代号。第二步,这个 JWT 被跨站 POST 到 bzr.openai.com\u002Fv1\u002Fobi\u002Fsync,响应通过 Set-Cookie 把 __obi 写入 .openai.com,1 年有效期,SameSite=None;Secure。第三步,广告主网站随后通过 OpenAI 的广告像素 SDK 发出的任何请求——包括单纯加载 SDK 脚本本身——浏览器都会自动附上这个 cookie,请求被 bzr.openai.com 返回 202 Accepted 接收。\n\n研究者在 932 个解码出的 sync token 中发现,736 个是登录态(主体类型为 account_user),196 个是匿名态(主体类型为 anonymous),匿名标识同样稳定,一台设备一份,持续至少 27 天。\n\n## 数据负载与同意绕开\n\n随 cookie 一起被回传的还包括从广告主页面抓取的身份信号,SDK 自己把数据来源分成四类:in(广告主显式传入)、fm(表单字段抓取)、js(从 GTM\u002FAdobe dataLayer 拦截)、ht(渲染页面文本)。研究者在流量样本中观察到,被 SDK 抓取的来源(685 次)几乎是广告主主动提供的(255 次)的 3 倍。邮箱、电话、姓名 SHA-256 哈希后传输,而国家、地区、城市、邮编明文发送——邮编是被抓取最频繁的字段,在 28 个站点共观察到 100 次。\n\n研究者 9 月 14 日向 OpenAI 的 press 与 privacy 邮箱分别发信,提出了两个直接问题:第一,为什么 __obi 被归类为分析 cookie 而不是营销 cookie;第二,如果用户拒绝营销同意但接受分析同意,是否仍会收到这个 cookie。OpenAI Support 确认收到问题并表示会内部评审,截至披露日两个问题都未得到实质性答复。\n\n## 这件事真正的分量\n\n这并不是一次新的攻击,而是 OpenAI 自身广告产品线的标配基础设施,设计上完全合规、配置上完全公开。但它的配置细节暴露了三个值得讨论的问题。第一,SameSite=None 是 cookie 跨站可携带的唯一必要条件,而 OpenAI 策略中只有 __obi 这一个 cookie 走这条路,这是有意为之的产品决策,不是技术疏漏。第二,OpenAI 把 __obi 归类为「分析 cookie」而非「营销 cookie」,绕开了用户只授权分析而拒绝营销这一常见设置——cookie 同意弹窗里那个看似无害的分析开关,实际上足以让广告标识被写入。第三,把广告 SDK 集成进商家网站,与 Meta Pixel、Google Ads Tag 在结构上没有区别;真正不同的是承载它的产品——人们向一个对话式 AI 倾诉的内容,和向搜索引擎\u002F社交网络暴露的内容,在隐私直觉上从来不在同一个量级。\n\n研究者的复现明确指出几个边界:第一,这个机制在 Safari 和任何 iOS 浏览器上被 ITP 默认拦截;Firefox 的 Total Cookie Protection 和 Brave 也同样默认阻断;只有 Chrome for Android 被验证复现成功,桌面 Chrome 未测试。第二,大约每 5 次 ChatGPT 会话中只有 1 次会触发 sync token;移动 Web 版有时根本不触发。第三,OpenAI 服务端把 __obi 与账户的对应 join 在设计上必然存在(否则没必要在 JWT 里带 sub),但研究者没能在流量层直接观测到服务端 join。\n\n## 实操层如何自检\n\n对用户而言,排查路径相对清晰。Safari 用户(包括所有 iOS 浏览器)无需操作,ITP 默认拦截所有第三方 cookie,机制直接失效;Firefox 默认开启 Total Cookie Protection、Brave 默认开启站点隔离,效果相同。Chrome 用户需要在设置里手动开启第三方 cookie 阻断并搭配 uBlock Origin。最稳妥的做法是周期性清理 .openai.com \u002F chatgpt.com 下的 cookie,虽然下次 ChatGPT 会话可能再次写入。\n\n对开发者与广告主而言,这件事提出了一个尴尬的现实:你安装了 OpenAI 的转化标签,你看不到自己的访客正在被打成 ChatGPT 账户标识,__obi 的域不可读,你没法审计,也无法拒绝。这是广告 SDK 黑盒化带来的新一阶风险——你卖的流量你看不到,但卖你流量的平台看得到。OpenAI 在披露日的沉默,让这个机制暂时停留在「合法但未充分告知」的位置。对 ChatGPT 用户而言,这件事真正的提示是:在「同意分析」和「同意营销」两个看似并行的开关背后,可能藏着第三层跨产品关联,而你点下的那个看似无害的按钮,是这一切的开端。","https:\u002F\u002Fwww.buchodi.com","6d888cdc-fc64-4ddb-bae5-dc53f5329740",[11,15,18,21],{"id":12,"name":13,"slug":13,"description":14,"color":14},"c33b1bbc-d6ce-4f61-9d5d-1a0704a6a09b","ai-policy",null,{"id":16,"name":17,"slug":17,"description":14,"color":14},"1fcfaaf2-67de-43d3-9e35-5784852fec60","ai-safety",{"id":19,"name":20,"slug":20,"description":14,"color":14},"01598627-1ea6-4b27-a5d8-874971571a71","llm",{"id":22,"name":23,"slug":23,"description":14,"color":14},"42e59a88-7795-47dc-a334-ef1e72c24347","openai",[25],{"id":26,"lang":27,"title":28,"summary":29,"content":30},"2f6ae717-5676-4ce5-83b8-1a0076a0fa02","en","ChatGPT's __obi cookie follows you off-site for a year","Sept 20 disclosure: ChatGPT sets a 1-year __obi cookie on .openai.com — the only OpenAI cookie configured to travel cross-site via the ad SDK.","The most striking AI privacy story of the past few weeks was not a vulnerability or a P0 incident. It was a cookie written into OpenAI's own published cookie policy, configured explicitly to be carried across sites.\n\n## The Sept 20 disclosure\n\nIndependent researcher Jamie Larson published a long-form writeup on Buchodi Threat Intel on September 20, detailing how the ad collector at bzr.openai.com writes a cookie called __obi. Scope: .openai.com. Lifetime: one year. SameSite=None; Secure. That combination is the only configuration that lets a browser send a cookie on cross-site requests, and every other identifier in OpenAI's policy is configured SameSite=Lax or scoped to a domain that prevents the cross-site trip.\n\nThe researcher reproduced the full chain on his own phone, verified it with two independent capture methods, and cross-checked it against 23,929 requests across 936 advertiser pixels on 1,029 hostnames. When a user later visits a site that has installed OpenAI's advertiser pixel, the cookie is attached to the pixel's request back to OpenAI's ad infrastructure. OpenAI can connect the user's behavior on those sites — products searched, articles read, purchases made — back to the ChatGPT account.\n\n## The mechanism, step by step\n\nStep 1: the client on chatgpt.com generates 16 random bytes and calls \u002Fbackend-api\u002Fbazaar\u002Fobi\u002Fsync-token. OpenAI's backend returns an RS256 JWT containing the account's sub field, an obi identifier, and a 60-second expiry. The issuer is chatgpt-wadi; the audience is bzr.openai.com (bzr is OpenAI's internal name for its ads platform).\n\nStep 2: that JWT is POSTed cross-site to bzr.openai.com\u002Fv1\u002Fobi\u002Fsync, and the response sets __obi on .openai.com with Max-Age=31536000 and SameSite=None; Secure.\n\nStep 3: any subsequent request from an advertiser site to OpenAI's ad infrastructure — including simply loading the pixel's \u003Cscript src> tag — automatically carries the cookie. OpenAI's bzr.openai.com accepts it with 202 Accepted.\n\nAcross 932 decoded sync tokens, 736 were logged-in (subject_type: account_user), 196 were anonymous (subject_type: anonymous). The anonymous identifier is just as persistent: one per device, observed persisting at least 27 days.\n\n## The data payload and the consent bypass\n\nAlong with the cookie, the SDK also harvests identity signals from the advertiser's page. The SDK itself labels four sources: in (advertiser-supplied), fm (form-field scrape), js (intercepted from GTM\u002FAdobe dataLayer), ht (rendered page text). In the observed traffic, scraped sources combined for 685 events versus 255 for advertiser-supplied — scraped identity outnumbered deliberate identity roughly 3-to-1.\n\nEmail, phone, and first\u002Flast name are SHA-256 hashed before transmission; country, region, city, and postal code are sent in clear text. Postal code was the most-harvested field — 100 events across 28 sites.\n\nOn September 14, the researcher emailed OpenAI's press and privacy teams with two direct questions: why is __obi classified as an analytics cookie rather than a marketing cookie, and does a user who accepts analytics consent but declines marketing consent still receive the cookie. OpenAI Support acknowledged receipt and said the inquiry would be shared internally for review. As of disclosure, neither question has been substantively answered.\n\n## What this actually means\n\nThis is not an exploit. It is OpenAI's own ad product infrastructure, fully compliant, fully documented in OpenAI's own policy. But the configuration details expose three questions worth discussing.\n\nFirst, SameSite=None is the only configuration that allows a cookie to travel cross-site, and __obi is the only cookie in OpenAI's policy configured that way. That is an intentional product decision, not a technical oversight.\n\nSecond, classifying __obi as an analytics cookie rather than a marketing cookie lets it slip past the consent toggle most users would actually read. A user who explicitly refuses marketing consent but accepts the apparently-benign analytics consent will still get the identifier. The \"consent\" model in OpenAI's cookie banner is structured in a way that allows exactly this routing.\n\nThird, integrating an ad SDK into merchant sites is structurally identical to Meta's Pixel or Google's ads tag — what is different is the product it rides on. People tell a conversational AI things they would never type into a search box or post on a social feed: a diagnosis they have not told their family, a legal problem they are embarrassed about, a relationship they are working through. The privacy intuition around an AI chat product has never been the same as around a search or social network, even when the tracking plumbing is.\n\nThe reproduction makes several limits explicit. Safari (and any iOS browser) blocks this mechanism by default via ITP; Firefox's Total Cookie Protection and Brave do the same. Only Chrome for Android was verified to reproduce it; desktop Chrome was untested. Roughly one in five ChatGPT sessions produces a sync token; the mobile web client sometimes serves ads without syncing at all. The server-side join between __obi and a ChatGPT account follows from the design but was not directly observed in traffic.\n\n## What users and developers should actually do\n\nFor users, the path is clear. Safari and iOS users need nothing; ITP blocks third-party cookies by default. Firefox's Total Cookie Protection and Brave work the same way. Chrome users need to enable third-party cookie blocking in settings and pair it with uBlock Origin. Periodically clearing cookies for .openai.com and chatgpt.com is the most reliable belt-and-suspenders approach, even though the next ChatGPT session will set it again.\n\nFor developers and advertisers, the story is more uncomfortable. You installed OpenAI's conversion tag; you cannot read __obi (it lives on a domain your scripts cannot access); you cannot audit it; you cannot refuse it. The buyer of your traffic has visibility into your customers that you do not have. That is a new tier of black-box risk in ad SDKs, and OpenAI's silence as of disclosure leaves the mechanism in a state that is legally defensible but not adequately disclosed.\n\nFor ChatGPT users, the real lesson is the gap between the consent toggles they think they are configuring and the cross-product linkage that is actually being built. The button labeled \"Accept analytics\" is, in this mechanism's case, the start of something broader than its label suggests.","openai-obi-cookie-cross-site-tracking","2026-09-30T00:00:00Z","2026-09-30T03:06:18.445573Z","2026-09-30T03:06:18.445587Z",true,"agent",128,[39,48],{"slug":40,"tag_slug":40,"title_zh":41,"title_en":42,"intro_zh":43,"intro_en":44,"id":45,"is_active":35,"created_at":46,"modified_at":47},"ai-for-science","AI for Science 2026：从 UniPert 到 GPT-Rosalind 的硬核进化","AI for Science 2026: from UniPert to GPT-Rosalind","生命科学、化学材料、物理世界模型——AI 正在从\"语言工具\"变成\"实验伙伴\"。本专题收录 AI 在三大科学方向的关键节点：UniPert 统一基因与化学扰动空间、GPT-Rosalind 端到端生命科学推理、达摩院 AI 智能体 28 小时找到 4 种超导新材料、Anthropic Claude Science 把工作台做成标准品。","From language tool to lab partner — AI is reshaping life sciences, chemistry\u002Fmaterials, and physical world models. This topic covers the key milestones: UniPert unifying genetic-chemical perturbation spaces, GPT-Rosalind's end-to-end life-sciences reasoning, DAMO's AI agent discovering 4 superconducting materials in 28 hours, and Anthropic's Claude Science workbench going mainstream.","988a4300-5fab-41c4-b5d8-63711a2dc757","2026-09-10T01:34:15.296649Z","2026-09-10T01:34:15.296663Z",{"slug":49,"tag_slug":49,"title_zh":50,"title_en":51,"intro_zh":52,"intro_en":53,"id":54,"is_active":35,"created_at":55,"modified_at":56},"h3-series","MiniMax H3 系列：从开源权重到 35 倍吞吐","MiniMax H3 Series: from open weights to 35x throughput","MiniMax H3 自 2026 年 8 月开源以来节奏密集：官方把生成、参考与编辑收回一个模型；ComfyUI 当天压进 RTX 3060；摩尔线程 3 小时完成国产 GPU 适配；fal 后训练版把吞吐拉到 35 倍；FastH3 蒸馏再砍推理成本。本专题持续追踪 H3 的发布—开源—蒸馏—部署全链路。","Since MiniMax open-sourced H3 in August 2026 the pace has been relentless: one unified omni-modal model, same-day ComfyUI support down to an RTX 3060, a 3-hour Day-0 port to Moore Threads GPUs, fal's post-trained H3 Max at 35x throughput, and FastH3 distillation cutting inference cost further. This topic tracks the full H3 chain — release, open weights, distillation, deployment.","83ef0daa-3c31-4cb3-86ed-e5ee58654d5f","2026-09-08T07:33:19.942193Z","2026-09-08T07:33:19.942209Z",{"items":58},[59,64,69,74,79,84],{"id":60,"title":61,"news_slug":62,"published_at":63},"9cae377e-d048-4d0e-af78-8cba3e1cf5b4","法庭文件揭微软高管私下定性 AI 抓取为最大盗窃","ai-scraping-largest-theft-hecht-memo","2026-09-29T04:00:00+00:00",{"id":65,"title":66,"news_slug":67,"published_at":68},"e0642de2-5fec-472b-b85e-c63ccbad3b75","Anthropic 研究员公开辞职:AI 巨头正「拿全人类的命豪赌」自我进化超级智能","anthropic-coxon-resigns-ai-extinction-fears","2026-09-24T06:30:00+00:00",{"id":70,"title":71,"news_slug":72,"published_at":73},"7fce8217-577f-4fd5-8f88-a1566cbf1290","微软与 OpenAI 法庭文件解封:LLM 训练数据被自家高管称为史上最大劳动窃取","microsoft-openai-doom-loop-nyt-copyright-2026","2026-09-23T05:03:20+00:00",{"id":75,"title":76,"news_slug":77,"published_at":78},"d54e1ab3-820a-45fd-a4e9-ccbf6802bd72","NYT vs OpenAI 案解封:微软高管承认 AI 抓取是「最大劳动盗窃」","nyt-openai-microsoft-hecht-largest-theft-of-labor","2026-09-23T03:00:00+00:00",{"id":80,"title":81,"news_slug":82,"published_at":83},"a0bd8ffb-63fd-452b-9d0b-634baa62d704","OpenAI 二次暂停训练:一个 DNS 查询打通训练沙盒","openai-agent-dns-sandbox-escape","2026-09-28T14:00:00+00:00",{"id":85,"title":86,"news_slug":87,"published_at":88},"b74811e0-543f-46ac-86be-0ed1aceb07f6","AI 用 DNS 递话:OpenAI 二度暂停前沿训练","openai-agent-dns-sandbox-escape-frontier-pause","2026-09-27T15:13:00+00:00"]