Mind Your Business: AI Edition

At this point in the age of commercial AI adoption, I can safely assume that we’re all having a great time using and experimenting with a whole raft of exciting and time-saving AI tools. Even as I write this, my head is throbbing from all the attention-grabbing tweets and posts about the latest innovations and handy ChatGPT prompts for getting [insert hopes and dreams here].

I’m all for innovation, and AI, as we currently know it will completely change our world in so many ways. Still, being the crafty and morally onerous security professional that I am, I’m often drawn to seeing the dark side of such things. When it comes to artificial intelligence, the real impacts haven’t been seen yet.

So where am I going with this? Well, now that AI browser extensions are becoming a thing, I’ve been experimenting a bit here and there. Installing these extensions is extremely simple, which is a great user experience, of course, but I wanted to see what exactly I was about to allow in terms of external third-party connectivity. To no surprise, here’s what I got:

Given these AI browser extensions are mostly aimed at helping you be more creative and productive, it’s understandable why these tools need this type of access within your web browser. It’s also important to note that, for an extension to do its job, it will need permission to read and change the content of data and web pages you view in the browser.

Without this access, the extension will likely be pretty useless. With that being said, here are a couple of things to think about before diving in head first:

Angela Bohlke / Barcroft Images

Running third-party code in your browser:

Browser extensions come with their fair share of risks, and one of the main concerns is with their development. Often crafted by independent or inexperienced developers, third-party code may contain vulnerabilities due to coding errors or a lack of thorough, secure code practices. 

Sometimes, these projects are abandoned or neglected without any updates or patches to address emerging threats.

Receive (the) data you input:

As I mentioned earlier, these browser extensions will need access to the data you input for them to do their job effectively. This isn’t so much of an issue if you’re not sharing any sensitive information, but if you are, for example, trying to get AI to format some credit card numbers into a table or draft some financial reports using actual company data - this presents a significant risk with data exposure/leakage.

It can seem harmless on the surface, trying to save time and get important work done a lot faster, but at the end of the day, it is most important to remember the following:

  • ChatGPT and other AI tools are public websites; therefore, you should only share information that you would be comfortable with the public knowing.

  • Only use browser extensions from a trusted or reputable source. The more well-known and vetted extensions are better choices than those that aren’t. Sometimes, malicious extensions do manage to slip through the gaps.

  • Try and keep the browser extensions to a minimum. This will help keep your web browser lean and fast.


To summarise, the current wave of AI tools exploding into the mainstream has truly made for exciting times ahead. However, the usage of these tools can have some severe impacts if used carelessly. 

Always be mindful of the information you share when using these extensions and websites. It’s perfectly fine to be curious and eager to experiment but treat it as just that, an experiment. You wouldn’t post highly sensitive information on Facebook, so don’t use it with AI, either.

Previous
Previous

Attack Surfaces - The Key To An Effective Threat Mitigation Strategy

Next
Next

The Cure For Phishing May Be More Phishing!