Comment by chen_dev

5 days ago

fyi, the cloud env is MITM. tested https://gmail.com with curl and browser including downloaded firefox: OpenAI-issued certificate: Subject: CN=gmail.com Issuer: O=OpenAI, LLC; CN=openai.com Certificate verification: passed Response: 301 redirect to https://mail.google.com/mail/u/0/

This is a bit scary, this means they can even see the content of user's mail given the browser does not do any pin cert on the linux.

  • It's running on their machines. They can already see everything anyway. TLS MITM is exactly the right move especially given the history of their agents graffiti-ing the internet. They need to keep an eye on what the dots are doing centrally and be able to block it, even if the LLM delegated to some random third party program so agent logs themselves aren't helpful.

  • Also of every request you send with your language's request library if you use default settings. And they can do it without you being able to detect it.