The Verge - Artificial Intelligences 2024年07月12日
The Rabbit R1 has been logging users’ chats — with no way to wipe them
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

Rabbit R1 是一款 AI 助理设备,此前被发现存在隐私漏洞,用户聊天记录存储在设备上无法删除。Rabbit 公司已发布软件更新,新增“恢复出厂设置”功能,允许用户完全删除设备上的本地用户数据。此外,更新还修复了另一个漏洞,之前设备的配对数据可以读取用户的 Rabbithole 日志,现在配对数据将无法读取日志,并且不再记录到设备上。

🐇 **无法删除聊天记录:** Rabbit R1 之前没有提供“恢复出厂设置”功能,用户聊天记录存储在设备上无法删除,这引发了用户对隐私的担忧。

🔐 **配对数据读取日志:** 除了无法删除聊天记录外,R1 设备的配对数据还拥有读取 Rabbithole 日志的权限,这意味着被盗或黑客攻击的 R1 设备可以获取用户的请求、照片等信息。

🛡️ **软件更新修复漏洞:** Rabbit 公司已发布软件更新,新增“恢复出厂设置”功能,用户可以完全删除设备上的本地用户数据。更新还修复了配对数据读取日志的漏洞,配对数据将无法读取日志,并且不再记录到设备上。

📝 **安全审查:** Rabbit 公司表示将进行全面的设备日志记录实践审查,以确保其符合其他领域的安全标准。

⚠️ **潜在风险:** 尽管 Rabbit 公司表示没有迹象表明配对数据被滥用来获取前设备所有者的 Rabbithole 日志数据,但安全研究人员发现,对设备进行越狱操作可以获取硬编码的 API 密钥,这仍然存在潜在风险。

There wasn’t a Factory Reset option, previously. | Photo: David Pierce / The Verge

Since the launch of the Rabbit R1, the AI assistant device has been storing users’ chat logs on-device with no way to erase them, according to a company security bulletin. Rabbit is now addressing the issue with a software update that includes a new Factory Reset option in settings to wipe the device. Previously, you could only unlink your account from an R1, which did not erase all user data.

Along with the new ability to fully delete local user data, the software update also addresses another eyebrow-raising behavior of the R1. Prior to the update, stored pairing data that lets the R1 hardware add things to the Rabbithole journal also had permission to read the journal as well. That means a stolen and hacked R1 could potentially have handed over users’ saved requests, photos, and more.

With the update, R1’s pairing data can no longer read the journal and is no longer logged to the device, and Rabbit has reduced the amount of log data stored on the device. The company says there’s “no indication that pairing data has been abused to retrieve rabbithole journal data belonging to a former device owner.”

Rabbit’s security bulletin paints the issue as a relatively inconsequential risk with its example that a stolen and jailbroken R1 could reveal to a bad actor the last weather log asked by the original owner. Security researchers last month found that a jailbreak of the device could also hand out hardcoded API keys. The company promises to improve security practices and “prevent similar issues in the future,” saying it’s performing a full review of device logging practices to ensure it aligns with its standards “set in other areas.”

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

Rabbit R1 AI 助理 隐私漏洞 安全更新 数据删除
相关文章