Settings

Theme

What is real importance of the OAuth *state* parameter is?

1 points by DBformore 2 years ago · 2 comments · 1 min read


A lot of developers are not sure about the answer.

Security researchers from Salt could install malicious ChatGPT plugins, just because of a minor state mistake that ChatGPT made.

If you want to understand OAuth, this post is for you: https://salt.security/blog/security-flaws-within-chatgpt-extensions-allowed-access-to-accounts-on-third-party-websites-and-sensitive-data

MorL 2 years ago

Could you elaborate? What do you mean by "could install malicious ChatGPT plugins" ?

  • DBformoreOP 2 years ago

    ChatGPT plugins (think mini-apps for ChatGPT) expand functionality to ChatGPT but introduce new attack vectors. Those security researchers could install a malicious ChatGPT, that they wrote, on another victim account.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection