The Digital Security Digest, by Freedom of the Press Foundation (FPF), is a weekly newsletter with security tips that keep you, your sources, and your devices safe. If someone shared this newsletter with you, please subscribe here.

Make ChatGPT talk to your friends and family so you don’t have to

On Aug. 20, OpenAI announced a new plug-in for Apple’s Messages app that allows ChatGPT to read, summarize, draft, and send messages. You will be prompted to approve messages before sending them, or you can have them sent automatically. This feature is available within ChatGPT’s desktop app, as well as in the ChatGPT Work agent and its software-writing tool, Codex. It’s currently unclear how, or if, Apple was directly involved in the development of this feature.

After reaching out to OpenAI for comment, TechCrunch reports, “The company also said that content from messages is stored locally on a user’s computer and is not saved to the company’s servers.” Instead, users may optionally save conversation data to the cloud.

What you can do

Ordinarily, messages sent from your Apple Messages app are end-to-end encrypted between iMessage users. In recent months, using a newer messaging standard called RCS, more messages than ever between Apple and Android users have support for end-to-end encryption as well. But the emergence of AI tools to control your devices and apps — and to automate messaging — could undermine the promise of end-to-end encryption. We don’t always know if the people we’re talking to have allowed a chatbot controlled by a private company into the conversation, nor do we know if someone in the chat has allowed a message to be sent to a third party.

Perhaps your gut reaction to this news was like mine: This sounds like a privacy nightmare.

  • More than a technology problem, this is a human trust problem. This particular plug-in runs locally on your own computer, rather than processing your messages on a cloud server. Someone would need to choose to save your messages with OpenAI. They could just as easily take screenshots of your messages and store them on any other cloud provider. This could also happen on Signal, or any other encrypted messaging app. So the question is, are you talking to someone who will respect your privacy? Though AI amplifies the risk, this problem has always been there.
  • Understand where your data is processed and stored. As Signal’s President Meredith Whittaker argues, AI agents that are connected to cloud providers typically need to be able to read your data in order to process it. If you can’t assess the risk for your purposes, the safest move is to avoid using these tools to process messages in the first place.
  • You don’t need OpenAI for this! If you do want to use this feature, but don’t want OpenAI all up in your business, Apple is already planning to include this feature in Siri AI starting this fall, with the release of iOS 27, iPadOS 27, and macOS 27. This will run on-device using Apple’s Private Cloud Compute, which handles complex queries while preventing the tech company itself from seeing your requests.

Updates from our team

In case you missed it, IndieWire highlighted our digital security training series for filmmakers, offered in collaboration with friends at Field of Vision. Check it out. We’ve already kicked off the training, but there’s even more to come. The series covers risk assessment, secure communication, travel safety, footage protection, digital footprint management, and AI in filmmaking. So, if you are a filmmaker or want to share this with a filmmaker in your life, we hope you’ll sign up here.

Our team is always ready to assist journalists with digital security concerns. Reach out here, and stay safe and secure out there.

Best,
Martin

Martin Shelton
Deputy Director of Digital Security
Freedom of the Press Foundation