Hackers can read private AI assistant chats even though they're encrypted
arstechnica.com
arstechnica.com
Mitigating this should be very simple—pad the token with null to some reasonable length before sending it, then clip it on the client side. This would result in slightly higher bandwidth usage, but not enough to be perceptible.
Cloudflare mitigates AI side channel attack | https://news.ycombinator.com/item?id=39703255
It also requires a full packet capture of the target making it not very easy to execute.
sure, now that they know about it
Nit: Title should say “guess” and not “read”.