You're paying AI companies a monthly subscription fee to be fingerprinted like a parolee.

I got bored and ran uBlock across Claude, ChatGPT, and Gemini simultaneously.

Claude:

  • Six parallel telemetry pipelines.
  • A tracking GIF with 40 browser fingerprint data points baked into the URL, routed through a CDN proxy alias specifically to make it harder to block.
  • Intercom running a persistent WebSocket whether you use it or not.
  • Honeycomb distributed tracing on a chat UI because apparently your conversation needs the same observability stack as a payments microservice.

ChatGPT:

  • proxies telemetry through their own backend to hide the Datadog destination URL from blockers.
  • uBlock had to deploy scriptlet injection — actual JS injected into the page to intercept fetch() at the API level — because a network rule wasn't enough.
  • Also ships your usage data to Google Analytics. OpenAI. To Google. You cannot make this up.
  • Also runs a proof-of-work challenge before you're allowed to type anything.

Gemini:

  • play.google.com/log getting hammered with your full session behavior, authenticated with three SAPISIDHASH token variants, piped directly into the Google identity supergraph that correlates everything you've ever done across every Google product since 2004.
  • Also creates a Web App Activity record in your Google account timeline. Also has "ads" in one of the telemetry endpoint subdomains.

When uBlock blocks Gemini's requests, the JS exceptions bubble up and Gemini dutifully tries to POST the error details back to Google. uBlock blocks that too. The error messages contain the internal codenames for every upsell popup that failed to load.

KETCHUP_DISCOVERY_CARD.
MUSTARD_DISCOVERY_CARD.
MAYO_DISCOVERY_CARD.

Google named their subscription upsell popups after condiments and I found out because their error handler snitched on them.

All three of these products cost money.
One of them is also running ad infrastructure.

Touch grass. Install @ublockorigin

#infosec #privacy #selfhosted #foss #surveillance

@k3ym0 @ublockorigin What about Mistral ? This is the one I use.

@OlivierBurnier @ublockorigin

Mistral: two blocked requests.

Cloudflare Insights ("is the site up") and a single Intercom beacon POST that didn't even retry.

that's it. no Statsig. no tracking GIFs. no Google Analytics. no distributed tracing. no proof-of-work challenge. no KETCHUP_DISCOVERY_CARD. nothing.

a French AI company nobody talks about is running the cleanest frontend in the entire field by a factor of roughly 150x and we're all sleeping on it

les français ont tout compris

#mistral #privacy #infosec

@k3ym0 @OlivierBurnier @ublockorigin they also have a better data handling policy because they are based in the eu, iirc they don't share your chats with third parties under any circumstances (well police and government you know how they work) and if they identify any personal informations in your chats they don't process it for training
@k3ym0 @OlivierBurnier @ublockorigin that's because they have to comply with EU laws. I use LLMs very rarely but when I do I use Mistral.
Claude, Gemini and all the other US-American AI services have to comply to GDPR to, since they are offering services to European citizens. They just don't give a shit on it, and EU law is not yet enforced.
@Fokeu @k3ym0 @OlivierBurnier @ublockorigin

@kirschwipfel
there were already some penalties handed out which US government labelled as censorship.

@Fokeu @k3ym0 @OlivierBurnier @ublockorigin

@[email protected]#duckhange @OlivierBurnier @ublockorigin What is your take on duck.ai?
Further limiting user profiling by using the Tor Browser?

#chat #privacy #tor #duckduckgo

@k3ym0
The world should know since we beheaded our king 😁
@OlivierBurnier @ublockorigin

@k3ym0 @OlivierBurnier @ublockorigin

with offgpt no blocks from supranational mega platforms are needed :) and if you do not use LLMs for logic (which I would strongly recommend) - its faster and without ads doing the same translation / search a 20 times bigger model would do. Big like mistral, where its hard to ever become community owned..
We got useful prompts and ideas out by being a community owned Artificial Idiocracy - but we are still tiny - come join us :)