LLMs

PSA: Your Claude shared chats and Artifacts may have ended up on Google

Publicado porRedacao AIDaily
5 min de leitura
Autor na fonte original: Lorenzo Franceschi-Bicchierai

The issue appears to have originated from Claude’s “share chat” feature, which allows users to create links that enable anyone with the assigned URL view a conversation or project.

Compartilhar:

An untold number of Claude chats and Artifacts — the interactive mini apps and documents users can build inside Claude — were found publicly searchable on Google over the weekend, after Reddit users discovered that typing search operators like “site:claude.ai/share” into Google surfaced a long list of shared conversations. Some reportedly contained health records, private company documents, and the names and phone numbers of children.

The issue appears to have originated from Claude’s “share chat” feature, which allows users to create links that enable anyone with the assigned URL view a conversation or project. “Anyone with the link can view,” warns Claude’s interface. The language clearly implies that the feature is mainly intended to allow users to share their chats with friends, colleagues, and small groups — not the whole internet. Google Docs, for example, offers a similar feature and those documents don’t end up publicly accessible on Google.

Anthropic appeared to blame users for the exposure. When asked about what happened, the company told TechCrunch that share links only appear in search results when they’ve been posted somewhere search engines can see, like a forum or social media post; it added that a link sent privately to someone stays out of search.

Spokeswoman Amie Rotherham added in an explainer that: “We give people control over sharing their Claude conversations publicly, and in keeping with our privacy principles, we do not share chat directories or sitemaps with search engines like Google. These shareable links are not guessable or discoverable unless people choose to share them themselves. When someone shares a conversation, they are making that content publicly accessible, and like other public web content, it may be archived by third-party services.”

The issue was first flagged by a Reddit user on Saturday and was first reported by 404 Media on Monday morning.

As of Monday afternoon, a test search by TechCrunch on Google following the method outlined in the Reddit post does not return any results, suggesting that the exposure has somehow been remediated.

Before the issue was fixed, Futurism reported finding “a detailed medical report of a real patient, clinical trial results that included patient names, documents sharing the names and phone numbers of primary school-aged children, company documents marked for internal use only, and employee reviews that included personal information about workers.”

Exposed Artifacts included code and work notes. In at least one case, Fortune reported , a chat labeled “shared by Anthropic” also showed Claude producing erotica.

Anthropic’s usage policy explicitly prohibits Claude from generating sexually explicit content, and getting a chatbot to produce material against its stated guidelines — through repeated or creatively framed prompting — is a pattern that has surfaced periodically across most major AI models. It isn’t yet clear from the exposed chat how the content in question was generated, and Anthropic has not yet responded to TechCrunch’s request for comment on this specific case.

Google spokesperson Ned Adriance told TechCrunch that “Neither Google nor any other search engine controls what pages are made public on the web, and these pages were indexed across many search engines. We give site owners clear controls to decide whether pages can be crawled or indexed, and we always respect those directives.”

Last year, Forbes reported a similar issue in which hundreds of Claude chats were indexed by search engines — at the time, Google estimated it had indexed just under 600 conversations before the pages disappeared from search results. How closely the current exposure tracks that scale hasn’t been independently confirmed, though multiple users reported finding shared conversations through the same type of Google search query used to surface last year’s cache. Also last year, 404 Media reported that a researcher was able to scrape around 100,000 ChatGPT conversations that had been set to be shared publicly.

To review which Claude chats you set to have a public link, go to Settings -> Privacy -> Shared Chats.

When you purchase through links in our articles, we may earn a small commission . This doesn’t affect our editorial independence.

Lorenzo Franceschi-Bicchierai is a Senior Writer at TechCrunch, where he covers hacking, cybersecurity, surveillance, and privacy.

You can contact or verify outreach from Lorenzo by emailing lorenzo@techcrunch.com , via encrypted message at +1 917 257 1382 on Signal, and @lorenzofb on Keybase/Telegram.

Scale faster. Grow your portfolio. Gain practical expertise. No matter your goal, Disrupt can empower you. Save up to $330 toda y!

SpaceX launches new V3 Starlink satellites but suffers another booster failure Sean O'Kane

SpaceX launches new V3 Starlink satellites but suffers another booster failure

SpaceX launches new V3 Starlink satellites but suffers another booster failure

Prentis, new AI lab co-founded by Reid Hoffman, Mark Pincus in talks to raise $100M Marina Temkin

Prentis, new AI lab co-founded by Reid Hoffman, Mark Pincus in talks to raise $100M

Prentis, new AI lab co-founded by Reid Hoffman, Mark Pincus in talks to raise $100M

US accuses American of allegedly wiping his phone using a ‘duress’ password during border search Zack Whittaker

US accuses American of allegedly wiping his phone using a ‘duress’ password during border search

US accuses American of allegedly wiping his phone using a ‘duress’ password during border search

Anduril reportedly in talks to raise funding at $100B valuation, more than 3x last year’s mark Ram Iyer

Anduril reportedly in talks to raise funding at $100B valuation, more than 3x last year’s mark

Anduril reportedly in talks to raise funding at $100B valuation, more than 3x last year’s mark

Tesla’s robotaxis are moving in reverse Sean O'Kane

How OpenAI’s human mistake led to the AI-powered hack on Hugging Face Lorenzo Franceschi-Bicchierai

How OpenAI’s human mistake led to the AI-powered hack on Hugging Face

How OpenAI’s human mistake led to the AI-powered hack on Hugging Face

Jack Dorsey is taking on Slack with Buzz, a group chat platform for teams and their AI agents Amanda Silberling

Jack Dorsey is taking on Slack with Buzz, a group chat platform for teams and their AI agents

Jack Dorsey is taking on Slack with Buzz, a group chat platform for teams and their AI agents

Pontos-chave

  • A exposição de dados sensíveis do Claude destaca a necessidade de medidas rigorosas de proteção de dados no setor de tecnologia.
  • A conscientização dos usuários sobre os riscos do compartilhamento de informações online é essencial para evitar incidentes semelhantes.
  • O incidente pode resultar em maior fiscalização e exigências de conformidade com a LGPD no Brasil.

Análise editorial

A exposição de conversas e artefatos do Claude, que permitiu o acesso a informações sensíveis, levanta preocupações significativas sobre a privacidade e a segurança de dados na era da IA. Para o setor de tecnologia brasileiro, isso serve como um alerta sobre a importância de implementar medidas rigorosas de proteção de dados, especialmente em ferramentas que facilitam o compartilhamento de informações. A responsabilidade pela segurança dos dados não deve recair apenas sobre o usuário, mas também sobre as plataformas que oferecem esses serviços.

Além disso, a situação destaca a necessidade de uma maior conscientização dos usuários sobre as implicações do compartilhamento de informações online. Embora a interface do Claude tenha alertado os usuários sobre a possibilidade de tornar suas conversas públicas, muitos podem não compreender completamente os riscos associados. Isso sugere que as empresas de tecnologia precisam investir em educação e transparência para garantir que os usuários estejam cientes das consequências de suas ações.

No contexto brasileiro, onde a Lei Geral de Proteção de Dados (LGPD) já estabelece diretrizes para o tratamento de dados pessoais, incidentes como este podem levar a um aumento na fiscalização e na exigência de conformidade por parte das empresas. As consequências legais e reputacionais para as empresas que falham em proteger os dados dos usuários podem ser severas, o que pode impactar a confiança do consumidor e a adoção de novas tecnologias.

Por fim, é crucial acompanhar como a Anthropic e outras empresas de IA responderão a este incidente. A forma como lidam com a situação pode definir não apenas a confiança do público em suas plataformas, mas também influenciar a regulamentação futura e as práticas de mercado em relação à privacidade e segurança de dados na tecnologia de IA.

O que esta cobertura entrega

  • Atribuicao clara de fonte com link para a publicacao original.
  • Enquadramento editorial sobre relevancia, impacto e proximos desdobramentos.
  • Revisao de legibilidade, contexto e duplicacao antes da publicacao.

Fonte original:

TechCrunch AI

Sobre este artigo

Este artigo foi curado e publicado pelo AIDaily como parte da nossa cobertura editorial sobre desenvolvimentos em inteligência artificial. O conteúdo é baseado na fonte original citada abaixo, enriquecido com contexto e análise editorial. Ferramentas automatizadas podem auxiliar tradução e estruturação inicial, mas a decisão de publicar, a revisão factual e o enquadramento de contexto seguem responsabilidade editorial.

Saiba mais sobre nosso processo editorial