The Hidden Security Risk in Your AI Accounts: Why Passwords Matter for ChatGPT, Claude, and More
The convenience of logging into artificial intelligence platforms like ChatGPT, Claude, and Perplexity with Google or Apple accounts may be creating a significant security vulnerability for users. Although OAuth permissions offer a streamlined login experience, many users are unaware that these accounts can be accessed without a dedicated password directly tied to the AI service itself, leaving them susceptible to unauthorized access.
The OAuth Illusion of Security
OAuth (Open Authorization) allows users to sign into websites and applications using existing accounts from providers like Google or Apple. When you choose “Continue with Google” or “Continue with Apple” on platforms like ChatGPT, it appears secure – and often is, to a degree. You’re leveraging the security protocols of your existing account. However, as Liz Steen, a West Seattle mediator and attorney, discovered, this convenience can come at a cost. The login process often bypasses the creation of a unique password for the AI account itself.
The Password-less Problem
Unlike traditional account creation, many AI platforms don’t automatically prompt users to set a dedicated password during onboarding. This results in an account that relies solely on the OAuth connection for authentication. This means if someone gains access to your Google or Apple account – even temporarily – they can potentially access your AI accounts without triggering alerts specific to those services. As Steen points out, an attacker logging in as “you” will appear as a legitimate login to Google or Apple, masking the unauthorized access.
The Ripple Effect: Connected Accounts and Third-Party Permissions
The risk extends beyond the AI platform itself. Google and Apple accounts are often linked to numerous other services – Pinterest, Adobe, Roblox, and more. An attacker gaining access through a password-less AI account could potentially leverage OAuth permissions to access these connected accounts as well. While users can revoke third-party app permissions in Google or Apple settings, they cannot revoke permission from an attacker’s account, meaning they may remain unaware of the breach.
Anthropic’s Standoff with the Pentagon and Broader AI Security Concerns
The focus on AI account security comes at a time of heightened scrutiny regarding the technology’s broader security implications. Anthropic, the creator of Claude, is currently embroiled in a legal battle with the Department of Defense after being designated a “supply chain risk” according to CNN. This designation, typically reserved for companies linked to foreign adversaries, stems from disagreements over the use of AI in military applications. While this case centers on national security concerns, it underscores the growing awareness of potential vulnerabilities within the AI ecosystem. Anthropic recently surpassed OpenAI’s ChatGPT in iPhone App Store downloads as reported by CNN, highlighting its increasing prominence and the importance of securing its platform.
Protecting Your AI Accounts: A Simple Solution
The solution is straightforward: add a dedicated password to your AI accounts. Steen recommends accessing the settings within ChatGPT, Claude, and other AI platforms to create a unique password. Ideally, she suggests using a passkey, such as a YubiKey or other hardware security device, for an added layer of protection. Regularly resetting security settings on all linked accounts is also crucial.
Key Takeaways
- Don’t rely solely on OAuth logins for AI platforms.
- Create a unique, strong password for each AI account.
- Consider using a passkey for enhanced security.
- Regularly review and revoke third-party app permissions in your Google or Apple accounts.
- Stay vigilant and monitor your accounts for any suspicious activity.
As AI continues to integrate into our daily lives, prioritizing account security is paramount. Taking a few simple steps to protect your AI accounts can significantly reduce your risk of unauthorized access and safeguard your personal information.
Worth a look