Discord's AI breaks its own TOS!

No Text To Speech
5 Feb 202406:38

Summary

TLDRこのビデオでは、DiscordのAIサマリー機能が自社の利用規約に違反している問題を解説しています。具体的には、ユーザーのデータ漏洩が指摘されており、削除されたメッセージのユーザーIDが依然としてアクセス可能であることが問題視されています。この問題は、個人情報の削除を保証するDiscordのプライバシーポリシーに反しています。さらに、ビデオではDiscordのAI機能の失敗例として、ClydeやAutomod AIなどが挙げられています。最後に、この問題を発見した人物がバグ報奨金として$750を受け取った事例が紹介されています。このビデオは、DiscordのAIサマリー機能の問題点とその影響、法的なリスクについて詳しく解説しています。

Takeaways

  • 💡このスクリプトはDiscordのAI要約機能のセキュリティ上の問題について説明しています。
  • 💡ユーザーがメッセージを削除しても、要約にはユーザーIDが表示されることが分かっています。
  • 💡これはDiscordのプライバシーポリシーに違反している可能性があることが指摘されています。
  • 💡報告されたこの問題について、Discordがどのように対処するかが不明です。

Q & A

  • DiscordのAIサマリー機能とは何ですか?

    -DiscordのAIサマリー機能は、ユーザーの会話をOpenAIを使用して要約する機能です。

  • なぜDiscordのAIサマリー機能が問題視されているのですか?

    -DiscordのAIサマリー機能が、ユーザーのデータを不正に漏洩し、Discord自身の利用規約に違反する可能性があるためです。

  • 具体的にどのようなセキュリティ問題が指摘されていますか?

    -ユーザーがメッセージを削除しても、AIサマリーを通じてユーザーIDやメッセージIDが漏洩し得るという問題が指摘されています。

  • このセキュリティ問題による個人への影響は何ですか?

    -削除したはずのメッセージに関する情報が第三者に漏れ、ハラスメントなどの被害につながる恐れがあります。

  • Discordのプライバシーポリシーではどのようなルールが設定されていますか?

    -ユーザーは自分が送信したメッセージを削除する権利があり、削除されたメッセージはユーザーの個人情報とともに完全に消去されるべきです。

  • なぜこの問題は法的な問題を引き起こす可能性があるのですか?

    -AIサマリー機能がDiscordのプライバシーポリシーに違反し、ユーザーの個人情報保護に関する法律に抵触する可能性があるためです。

  • Discordはこの問題にどのように対処する可能性がありますか?

    -問題の重大性を踏まえ、DiscordはAIサマリー機能を取り下げる可能性が高いです。

  • Discordの他のAI機能についての実績はどうですか?

    -Discordは過去に複数のAI機能をリリースしましたが、問題が発生し、いくつかの機能は取り下げられました。

  • Discordはこのようなバグを発見した場合、どのような対応をしますか?

    -Discordにはバグ報奨金プログラムがあり、バグを報告したユーザーには報奨金が支払われます。

  • このセキュリティ問題が初めて報告されたのはいつですか?

    -このセキュリティ問題は2023年5月に初めて報告されましたが、記事作成時点でまだ解決されていません。

Outlines

00:00

🚨ディスコードのAIサマリーが利用規約に違反

ディスコードのAIサマリー機能がユーザーデータの漏洩を引き起こし、自社の利用規約に違反していることが判明しました。この機能はOpenAIを使用してディスコードの会話を要約するもので、セキュリティ上の問題が発覚しました。特定のペンリーという人物がこの問題を発見し、ユーザーがメッセージを削除しても、特定のAPIリクエストを使用すると、削除されたメッセージのIDや参加者の情報が依然としてアクセス可能であることが明らかになりました。これにより、プライバシーの侵害やハラスメントのリスクが生じています。さらに、この問題はディスコードのプライバシーポリシーにも違反しており、法的な問題を引き起こす可能性があります。この問題は2023年5月から既知のものであり、未だに修正されていない状態です。

05:01

🤖ディスコードのAI機能の失敗と将来性

ディスコードのAI機能、特にAIサマリーは多くの問題を抱えており、他のAI機能も期待外れであることが指摘されています。AIチャットボットのClydeは不適切な言動で問題となり、他の機能もほとんど更新されていないか、計画通りに機能していない状態です。AIサマリー機能に関する最近の問題が明らかになったことで、ディスコードがこの機能を撤回する可能性が高いと分析しています。また、ディスコードはバグ報告に対して報酬を提供する制度を設けており、この問題を報告した人物は$750の報酬を受け取ったとのことです。このビデオでは、ディスコードのAI機能の現状と将来性について批判的な視点から分析を加えています。

Mindmap

Keywords

💡AI summaries

Discord's AI-powered chat summaries feature that summarizes conversations. It surfaces private user IDs even after messages are deleted.

💡privacy policy

Discord's policy governing use of private user data. The AI summaries feature violates this by exposing user IDs.

💡user ID

Unique identifier assigned to each Discord user. Remains visible via AI summaries even if messages are deleted.

💡data deletion

Ability to permanently delete your private messages per Discord's policy. But AI summaries retain trace data.

Highlights

Discord's AI summaries feature breaks their own terms of service by leaking private user data

Penley discovered an exploit where message IDs and user IDs are exposed even if messages are deleted

This allows harassing users even if they've deleted sensitive messages

Discord's privacy policy states users can delete messages and personal information should be removed

AI summaries break this by exposing user IDs of deleted messages

This has been an issue since May 2023 and is still not patched

Discord has failed at most previous AI attempts like Clyde and automod

The speaker predicts Discord will cancel AI summaries due to these issues

Transcripts

play00:00

you probably didn't know but discord's

play00:01

AI summaries break discord's own terms

play00:04

of service by leaking your data but how

play00:06

did this happen what are the

play00:08

repercussions and what is Discord going

play00:10

to do about it now I'm going to assume

play00:11

that you've never had the absolute

play00:13

pleasure of using discord's AI summaries

play00:15

now I'm in Discord experiment Tu will

play00:17

have the invite Link in the description

play00:18

so you can try it out yourself but

play00:20

there's this little scroll button up

play00:21

here and when you click on it you get

play00:22

this option to look at Discord AI

play00:25

summaries now what the summaries feature

play00:26

does is it uses open AI to summarize

play00:29

your Discord conversations and why am I

play00:31

saying this feature is an absolute

play00:32

pleasure to use well here's this example

play00:34

here a conversation about enabling a fax

play00:37

printer which if you click on it is just

play00:38

one message from someone named fax

play00:40

printer asking how to enable AI is going

play00:43

to be taking our jobs for sure actually

play00:45

for Discord that's definitely not the

play00:46

case because I don't think this AI

play00:48

summaries feature is going to last for

play00:50

long because there's a big massive issue

play00:52

with it and the issue with AI summaries

play00:54

was found by a very familiar face on

play00:56

this channel penley now I could be

play00:58

really lazy and boring and just read off

play01:00

of the screenshot but I've had two cups

play01:02

of coffee today I'm feeling it so I'm

play01:04

going to show you how this exploit Works

play01:06

in practice so when you're on a Discord

play01:07

server and you get these AI summaries

play01:09

it's actually something called a get

play01:11

request to discord's API it's like me

play01:13

ringing up Discord servers and saying

play01:14

yeah I need some summaries for this

play01:16

specific Channel but in these summaries

play01:17

we can see that there is a topic a

play01:19

summary short message IDs and people and

play01:22

this actually corresponds to the

play01:23

information shown in the summaries tab

play01:25

we can see that the title is

play01:26

impersonation issues the topic

play01:27

impersonation issues well like I said we

play01:29

can also see message IDs and we can also

play01:31

see the user IDs of everyone that is in

play01:34

the summary so let's say that Pokemon

play01:35

deletes their message if you go to the

play01:37

AI summaries tab they should not show up

play01:39

as an author anymore in fact every

play01:41

single person could delete their message

play01:43

except one there has to be one remaining

play01:45

message but if everyone deleted their

play01:46

message they will not show up as authors

play01:49

which is fine except if you go to

play01:51

insomnia or you just use anything and

play01:54

you send a get request to Discord if

play01:55

they delete all of their messages you

play01:57

will still be able to see their message

play01:59

IDs and the people that have partak in

play02:01

the summary so let's say there's an AI

play02:03

summary of someone talking about them

play02:04

coming out of the closet now whoever was

play02:06

chatting about that they realize maybe

play02:08

we should delete our messages so that

play02:10

people don't harass us so they delete

play02:12

all their messages talking about coming

play02:13

out of the closet but they just forget

play02:15

one so that it still remains in the AI

play02:17

summaries well let's say a homophobe

play02:19

joins the Discord server and they see a

play02:21

summary talking about someone coming out

play02:23

of the closet even with the messages

play02:24

deleted they could still go to insomnia

play02:26

send a get request and figure out

play02:28

everyone that talked about about the

play02:30

thread which means that the homophobe

play02:31

could see everyone involved in the

play02:33

thread and harass every single one of

play02:35

them so that is how this security issue

play02:37

could affect you personally but things

play02:39

get even worse because this whole entire

play02:41

security issue has legal repercussions

play02:44

now let's look at the rules by dran Van

play02:47

strangle but in discord's terms of

play02:48

service they have a privacy policy now

play02:50

this whole document basically dictates

play02:52

what Discord can and cannot do with your

play02:55

personal information and if you scroll

play02:56

down long enough there's a very

play02:58

important section you actually allowed

play03:00

to edit and delete specific pieces of

play03:02

information within Discord services this

play03:04

is like a fundamental Rule and the

play03:06

fundamental rule is that you can delete

play03:08

any message that you have sent on

play03:10

Discord if you have posted it and you

play03:11

still have access to the server or the

play03:13

space that you posted it what this means

play03:16

is that if you delete a message on

play03:17

Discord it should be deleted your

play03:19

personal information should not be

play03:21

attached to it in any way whatsoever

play03:23

your Discord user ID should all be wiped

play03:26

unless of course you've done something a

play03:28

little bit naughty so when what

play03:30

scenarios would Discord store your

play03:31

message even after you delete it well

play03:33

there's two main scenarios the first one

play03:35

is to comply with the law for example if

play03:37

you're planning a domestic terrorism

play03:39

attack on Discord Discord would save

play03:41

your messages even if you deleted it

play03:43

assuming of course they actually figure

play03:44

you out because they are required by law

play03:46

or if they get some sort of legal notice

play03:48

but the second scenario that Discord

play03:49

would store your messages is if you're

play03:51

reporting someone so if you go through

play03:53

the report message prompts and you go

play03:55

through everything Discord will store

play03:56

this message so that they can actually

play03:58

ban the person even after after you

play03:59

delete this message it's still going to

play04:01

be stored by Discord but here's the

play04:03

thing even with these AI summaries if

play04:05

you delete your message your user ID

play04:07

will still pop up that is your

play04:09

information and absolutely nowhere in

play04:12

this privacy policy I promise you

play04:13

absolutely nowhere it says that a

play04:15

like me some random Discord user can get

play04:18

some of the information of your message

play04:20

discord's own AI summaries is breaking

play04:23

discord's own privacy policy now I'm not

play04:27

a lawyer but I'm not sure about the

play04:28

legality of of all this and I want to

play04:30

point out that this has been an issue

play04:32

since May

play04:34

2023 and it still has not been patched

play04:37

at this time and what will Discord do

play04:40

about it well we need a little bit of

play04:42

backstory because here's the thing every

play04:44

single tech company on the planet loves

play04:46

Ai and Discord is no exception but

play04:49

Discord is the exception in terms of

play04:51

complete and utter failure because in

play04:54

this blog post talking about AI Discord

play04:55

announces a handful of AI features we

play04:58

first have Clyde Clyde is discord's AI

play05:01

chatbot Clyde says racial slurs Clyde

play05:03

tried to date underage people and if

play05:05

you're not up to date on the Discord

play05:07

news Clyde has been cancelled our next

play05:09

feature automod AI the way that it works

play05:11

is that it'd use AI to moderate your

play05:13

Discord server and see whether or not

play05:15

people are breaking the rules I've not

play05:16

seen any update to discord's automod AI

play05:19

whatsoever this feature is basically

play05:21

dead in the water we have Avatar remix

play05:23

which is just a Discord bot so nothing

play05:25

crazy there we have whiteboard with AI

play05:27

preview which is where you're supposed

play05:29

to be able to Draw Something in the

play05:30

Whiteboard and uh turn it into a magical

play05:32

AI image it doesn't exist in Discord so

play05:35

the final AI feature of Discord is

play05:37

conversation summaries it is an absolute

play05:40

hot mess of problems for Discord and I'm

play05:43

99% sure I am betting my left nut on

play05:45

this one that Discord is going to cancel

play05:47

AI summaries just like how they canceled

play05:50

every single AI feature that they tried

play05:52

to release W wamp and now that the cat

play05:54

is out of the bag with this problem

play05:56

chances are Discord is going to look at

play05:58

this summaries AI feature and just

play06:00

cancel it completely which means I get

play06:03

to save my left nut so this is a big win

play06:05

for me now one final thing I want to

play06:07

talk about in terms of these AI

play06:08

summaries leaking your user ID is that

play06:11

Discord will actually pay you money if

play06:13

you find bugs like this Discord has a

play06:15

bug Bounty and fortunately for us panle

play06:17

told us how much they got paid

play06:20

$750 which is a pretty fair chunk of

play06:22

change you could actually buy 42

play06:24

emergency fire blankets to put out the

play06:26

giant dumpster fire of a problem that AI

play06:28

summaries are Discord take notes here

play06:30

any hoot Gamers That's All She Wrote a

play06:32

pretty nerdy video and somehow if you

play06:34

made it this far then let me give you a

play06:36

kiss I love you sweetheart

Rate This

5.0 / 5 (0 votes)

Do you need a summary in English?