Remix.run Logo
▲ albert_e 3 hours ago

Security by obscurity -- such an age old anti-pattern!

I believe many AI tools like Gemini generate publicly accessible URLs when we click "Share" on any chat conversation -- and expect users to then own the lifecycle of that link

Depending on how the link gets handled -- by the browser, device OS, any hooks/plugins/extensions, aggressive telemetry, social media url previews, preload/prefetch, wrapping and url shortening, etc as it reaches the intended user -- there are countless ways in which the URL can be indexed and scraped

There was a issue not long ago when Claude artifacts were indexed en-masse by Google and other search engines

This is shockingly lax approach to data security and privacy by design

▲kevindamm 2 hours ago | parent | next [-]

The same assumptions are true about giving any human that shareable link. They could pass it on to anyone, screenshot it, paste it into their own session. This has been true since before "share with link" permissions on Docs and elsewhere.

If you click "provide a shareable link" you should decide (and behave) as though that made it public.

I'm not saying it's good privacy posture on the side of the companies, but how else do you think that would work if there isn't any authentication step for the person viewing it? Even with authentication, "three may keep a secret, if two of them are dead."

▲postalcoder 3 hours ago | parent | prev [-]

Chat UIs are a minefield of “if you accidentally click this your data will be shared or trained without you realizing it!”