Breaking
AI & MLDeveloping Story

OpenAI's Computer History logs your keystrokes

OpenAI's Computer History feature records clicks and typing, storing them unencrypted and expanding prompt injection risks.

··1 hour ago·4 min read
Laptop keyboard with illuminated keys and a bright screen.
Photo by ostudio on Unsplash

If you want to record whatever you do on a computer, send those records to OpenAI, use more ChatGPT tokens, and increase your vulnerability to prompt injection, then OpenAI has something for you.

It's called Computer History, an opt-in way to record your computer interactions across apps and websites as memories organized on a timeline.

Why would you want to do so? Maybe you found Chronicle, the predecessor of Computer History which compiled similar histories using screenshots, a bit too intrusive but don't mind Computer History's approach – recording input events and storing them unencrypted locally for 48 hours (or more), with a brief visit to OpenAI's servers.

From screenshots to keystrokes

Computer History is, to put it bluntly, a keylogging and event capture system. It replaces the screenshot-based approach of Chronicle with a more direct method of capturing user activity.

There was a time before eyeglass cameras, license plate readers, surveillance capitalism, and police drones when such snooping might have provoked an outcry from privacy advocates. But the tech industry has found it can outsource surveillance to its own customers and in so doing make the panopticon harder to protest once it becomes a personal choice.

How it works

"Computer History creates an interaction-event stream from allowed apps and websites," OpenAI's documentation explains. "Events can include clicks, typing, keyboard shortcuts, app switches, and context that macOS exposes through its accessibility system. Computer History periodically turns these events into text summaries and local memory files."

The AI biz makes a point of noting that Computer History does not capture screen images, microphone input, or system audio. Nor does it capture private-mode browsing.

Availability and consent

Off by default, Computer History is available for ChatGPT Pro, Business, and Enterprise users in the ChatGPT desktop app on macOS. Pro users can enable it individually; Business and Enterprise users need an admin to approve it. It's not available currently in the European Economic Area (EEA), Switzerland, or the United Kingdom or to those accessing ChatGPT via API key or Amazon Bedrock.

There are circumstances in which OpenAI suggests Computer History users might want to suspend the service if they have some scruples about capturing user activity in apps and websites without permission.

"Turn it off during communications with other people unless you have their prior express consent," the company advises, perhaps in acknowledgement of legal risk. "Consider pausing it or excluding apps that contain sensitive health, financial, or personal information."

Data handling and retention

Computer History interaction events are supposed to be saved locally for up to 48 hours before being deleted by ChatGPT and Codex. Events, however, get sent to OpenAI servers to generate memories, and those may be stored locally for longer periods of time and may be used in future chats that get passed back to OpenAI.

"OpenAI does not retain those event files after processing unless required by law and does not use them for training," the company says. While it has opposed demands for chat logs, it has nonetheless provided chat logs in response to legal process.

Security and privacy concerns

Computer History adds cost because it uses tokens during the summarization of activities and the creation of memory data. It also expands the prompt injection attack surface.

"Computer History increases the risk of prompt injection from content in apps and websites," the company says. "For example, if you visit a website containing malicious instructions, ChatGPT or Codex might follow those instructions."

OpenAI includes a warning in its documentation: "Computer History files can contain sensitive information. They are not encrypted by Computer History, and other programs running as your macOS user may be able to access them."

But at least you get a nice timeline of your recent activity.

Why it matters to you

Computer History represents a deeper integration of AI into your daily computing, but it comes with trade-offs. The unencrypted local storage means any other process running as your macOS user could read your activity logs. The prompt injection risk is not theoretical: a malicious website could hijack your ChatGPT or Codex sessions by embedding harmful instructions in content you view.

This feature also raises the stakes for consent. OpenAI's own advice to pause during communications with others unless you have their prior express consent suggests the legal and ethical grey areas are not fully resolved. For businesses, the need for admin approval for Business and Enterprise users is a guardrail, but the underlying data exposure remains.

As AI tools become more entwined with our digital lives, the convenience of a detailed timeline of your work may be tempting, but the security and privacy costs are worth weighing.

#openai#security#ai and ml#prompt injection#chatgpt

Sources

Iliyas

Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories