Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Stress may trigger hair loss by causing mitochondria to pop

    November 26, 2025

    Verizon lays out the danger of what T-Mobile is proposing

    November 26, 2025

    Schedule, TV channels, and more

    November 26, 2025
    Facebook X (Twitter) Instagram
    Wednesday, November 26
    Facebook X (Twitter) Instagram YouTube Mastodon Tumblr Bluesky LinkedIn Threads
    ToolcomeToolcome
    • Technology & Startups

      Save $900 on Sony’s Best Mirrorless Camera With This Early Black Friday Deal (2025)

      November 26, 2025

      The US Military Wants to Fix Its Own Equipment. Defense Contractors Are Trying to Shoot That Down

      November 26, 2025

      Amazon Workers Issue Warning About Company’s ‘All-Costs-Justified’ Approach to AI Development

      November 26, 2025

      The 11 Best Cooling Mattresses for Hot Sleepers (2025)

      November 26, 2025

      Our Favorite Wireless Headphones for iPhone Owners Are $150 Off

      November 26, 2025
    • Science & Education

      Stress may trigger hair loss by causing mitochondria to pop

      November 26, 2025

      This Black Friday deal saves 77% on a subscription to Paramount Plus — Enjoy the best nature and science documentaries for the price of your morning coffee

      November 26, 2025

      2,000-year-old gold ring holds clue about lavish cremation burial unearthed in France

      November 26, 2025

      Our favorite air purifier for allergies has dropped to its lowest-ever price

      November 26, 2025

      Artemis II Orion Spacecraft Stacked

      November 26, 2025
    • Mobile Phones

      Verizon lays out the danger of what T-Mobile is proposing

      November 26, 2025

      Is your Pixel gaslighting you? You are not alone

      November 26, 2025

      Apple’s $230 iPhone sock is sold out, but you can now get a very cheap fake version

      November 26, 2025

      T-Mobile Black Friday deals: get a free iPhone 17 Pro, Galaxy Z Flip 7, and so much more

      November 26, 2025

      My top 3 phone deals that truly stand out from the 60+ phone offers this Black Friday

      November 26, 2025
    • Gadgets

      Schedule, TV channels, and more

      November 26, 2025

      An indie studio says it’s at risk of closure after Valve banned its game from Steam

      November 26, 2025

      Black Friday subscription and streaming deals include huge savings on HBO Max, Apple TV+, MasterClass, Rosetta Stone and more

      November 26, 2025

      Beyond Good & Evil 2 is somehow still under development

      November 26, 2025

      December’s PS Plus Monthly Games include Lego Horizon Adventures and Neon White

      November 26, 2025
    • Gaming

      The Gathering Redoing Its Terrible Monster Hunter Drop

      November 26, 2025

      Marvel Rivals’ New Mode Sounds Like The Stuff That Crashes Your PC

      November 26, 2025

      EcoFlow Decided Profit Doesn’t Matter, 1800W Power Station Hits New All-Time Low for Winter Backup

      November 26, 2025

      Roborock Q7 M5+ Falls 40% Off, Self-Empty for 7 Weeks While You Forget It Even Exists

      November 26, 2025

      Black Ops 7’s Lack Of Novelty Is Oddly Comforting

      November 26, 2025
    • Cars

      Yangwang U9 Xtreme Sets New Nürburgring Record

      November 26, 2025

      A simple 4-point motorbike safety checklist

      November 25, 2025

      A New Era in Design Innovation

      November 25, 2025

      3 Aftermarket Exterior Additions for Your VW Golf

      November 24, 2025

      How To File A Claim In An Uninsured Driver Accident?

      November 23, 2025
    • PC Accessories

      Unpowered SSDs Do Indeed Slowly Lose Data

      November 25, 2025

      Microsoft’s Notepad; The Best Advertisement For Notepad++ There is

      November 24, 2025

      Podcast #845 – NVIDIA Printing Money, DDR5 Prices Skyrocket, AMD FSR Update, 80’s Retro, Fallout Mods and MORE

      November 22, 2025

      The New Framework Laptop 16 Has An Upgradable GPU!

      November 20, 2025

      WhatsApp Skipped A Very Basic Security Step

      November 20, 2025
    ToolcomeToolcome
    Home»Science & Education»Popular AI chatbots have an alarming encryption flaw — meaning hackers may have easily intercepted messages
    Science & Education

    Popular AI chatbots have an alarming encryption flaw — meaning hackers may have easily intercepted messages

    November 26, 2025No Comments4 Mins Read3 Views
    Facebook Twitter Pinterest LinkedIn Telegram Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email



    Cybersecurity researchers at Microsoft have identified a critical flaw in modern artificial intelligence (AI) systems that means conversations with chatbots may have been intercepted through attacks by hackers. This would bypass the encryption that is meant to keep chats private.

    The attack technique, called Whisper Leak, is a type of “man-in-the-middle attack” in which hackers can intercept messages as they are in transit between servers. It worked because the hackers were able to read the metadata of messages and therefore infer their contents.

    Researchers outlined the attack in a study uploaded Nov. 5 to the preprint arXiv database. They informed Large Language Model (LLM) providers in June 2025. Some, including Microsoft and ChatGPT developer OpenAI, responded by assessing the risk and deploying fixes. Other LLM providers, however, declined to implement fixes, citing various rationales. Some did not even respond to the new findings, said the researchers, who refrained from highlighting which specific platforms have neglected to apply the fixes.


    You may like

    “I am not surprised,” cybersecurity analyst Dave Lear told Live Science “LLMs are a potential goldmine, considering the amount of information that people put into them – and not to mention the amount of medical data that can be in them, now that hospitals are using them to sort through test data someone was bound to find a way to exfiltrate that information sooner or later.”

    Uncovering vulnerabilities in AI chatbots

    Generative AI systems like Chat GPT are powerful AI tools that can generate responses based on a series of prompts, as used by virtual assistants on smartphones. A subset of LLMs are trained on massive amounts of data to generate text-based responses.

    Conversations that users have with LLMs are normally protected by transport layer security (TLS), a type of encryption protocol that prevents communications from being read by eavesdroppers. But the researchers were able to intercept and infer contents through the metadata of the communications between a user and a chatbot.

    Metadata is essentially data about data, including size and frequency — and it can often be more valuable than the contents of messages themselves. Although the content of messages between people and LLMs remained secure, by intercepting the messages and analysing the metadata, researchers were able to infer the subject of the messages.

    Get the world’s most fascinating discoveries delivered straight to your inbox.

    They achieved this by analysing the size of encrypted data packets — a small formatted unit of data sent over a network — from LLM responses. Researchers were able to develop a series of attack techniques, based on the timings, outputs and sequence of token lengths, to reconstruct plausible sentences in the messages without having to bypass the encryption.

    In many ways, the Whisper Leak attack uses a more advanced version of the internet surveillance policies of the U.K. Investigatory Powers Act 2016, which infers content of messages based on sender, timings, size and frequency, but without reading the content of the messages themselves.

    “To put this in perspective: if a government agency or internet service provider were monitoring traffic to a popular AI chatbot, they could reliably identify users asking questions about specific sensitive topics — whether that’s money laundering, political dissent, or other monitored subjects — even though all the traffic is encrypted,” said security researchers Jonathan Bar Or and Geoff McDonald in a blog post published by the Microsoft Defender Security Research Team.

    There are various techniques that LLM providers could utilize to mitigate this risk. For example, random padding — adding random bytes to a message to disrupt inference — could be appended to response fields, thereby increasing their length and reducing predictability by distorting packet sizes.

    The flaw at the heart of Whisper Leak but an architectural consequence of how LLMs are deployed. Mitigating the vulnerability is not an insurmountable challenge, but fixes have not been universally implemented by all LLM providers, the researchers said.

    Until providers are able to address the flaws in chatbots, the researchers said that users should avoid discussing sensitive topics on untrusted networks and to be aware of whether their providers have implemented mitigations. Virtual private networks (VPNs) can also be used as an additional layer of protection because they obfuscate the user’s identity and location.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    mehedihasan9992
    • Website

    Related Posts

    Stress may trigger hair loss by causing mitochondria to pop

    November 26, 2025

    This Black Friday deal saves 77% on a subscription to Paramount Plus — Enjoy the best nature and science documentaries for the price of your morning coffee

    November 26, 2025

    2,000-year-old gold ring holds clue about lavish cremation burial unearthed in France

    November 26, 2025

    Our favorite air purifier for allergies has dropped to its lowest-ever price

    November 26, 2025

    Artemis II Orion Spacecraft Stacked

    November 26, 2025

    Our top star projectors we’ve tested that are on sale for Black Friday this week

    November 26, 2025
    Leave A Reply Cancel Reply

    Top Posts

    These Galaxy phones were attacked by spyware for nearly a year before a patch was released

    November 10, 202528 Views

    Rumored Verizon decision will let down both customers and employees

    November 7, 202526 Views

    World’s biggest spiderweb discovered inside ‘Sulfur Cave’ with 111,000 arachnids living in pitch black

    November 4, 202521 Views
    Don't Miss

    Stress may trigger hair loss by causing mitochondria to pop

    November 26, 2025

    Scientists are connecting the dots between stress and hair loss, including a common condition that…

    Verizon lays out the danger of what T-Mobile is proposing

    November 26, 2025

    Schedule, TV channels, and more

    November 26, 2025

    The Gathering Redoing Its Terrible Monster Hunter Drop

    November 26, 2025
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    8.9

    Review: Dell’s New Tablet PC Can Survive -20f And Drops

    January 15, 2021

    Review: Kia EV6 2022 The Best Electric Vehicle Ever?

    January 14, 2021
    72

    Review: Animation Software Business Share, Market Size and Growth

    January 14, 2021
    Most Popular

    These Galaxy phones were attacked by spyware for nearly a year before a patch was released

    November 10, 202528 Views

    Rumored Verizon decision will let down both customers and employees

    November 7, 202526 Views

    World’s biggest spiderweb discovered inside ‘Sulfur Cave’ with 111,000 arachnids living in pitch black

    November 4, 202521 Views
    Our Picks

    Stress may trigger hair loss by causing mitochondria to pop

    November 26, 2025

    Verizon lays out the danger of what T-Mobile is proposing

    November 26, 2025

    Schedule, TV channels, and more

    November 26, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Toolcome
    Facebook X (Twitter) Instagram YouTube Mastodon Bluesky
    • Home
    • Technology
    • Gaming
    • Mobile Phones
    • Cars
    • PC Accessories
    © 2025 Tolcome. Designed by Aim Digi Ltd.

    Type above and press Enter to search. Press Esc to cancel.