跳到主要內容

ChatGPT追蹤cookie評測:關掉行銷選項仍被__obi跟蹤 | ChatGPT Tracking Cookie Review: Opt-Out Doesn't Stop __obi

By Kit 小克 | AI Tool Observer | 2026-09-21

🇹🇼 ChatGPT追蹤cookie評測:關掉行銷選項仍被__obi跟蹤

ChatGPT追蹤cookie「__obi」是什麼?

資安研究團隊在2026年9月20日公開一份報告,起底OpenAI在ChatGPT裡埋的__obi追蹤cookie——這是一個綁定在.openai.com網域、效期長達一年的跨站追蹤機制,會把你登入的ChatGPT帳號,跟你在其他網站上的瀏覽行為串在一起。研究員9月14日先私下通報OpenAI,官方回應了但拒絕說明cookie分類與用戶同意處理方式,一週後報告才公開。

__obi怎麼運作:三步驟跨站定位你

技術細節其實不複雜:

  • ChatGPT先在瀏覽器端產生一組隨機識別碼
  • 向OpenAI伺服器請求一個綁定你帳號的簽章JWT權杖
  • OpenAI在.openai.com設下__obi cookie,並允許它跨站傳輸

之後只要你造訪有安裝OpenAI廣告追蹤像素的網站——研究員實測發現至少橫跨Chewy、Wayfair、HelloFresh、Coursera、SeatGeek等12個商業網站、13組不同像素ID——__obi就會連同你的Email、電話、郵遞區號一起傳回OpenAI。分析932組解碼後的權杖,736組能精確對應到特定帳號;881個像素中有638個開啟了自動資料比對。

誰被追蹤?誰沒事?

  • 免費用戶:約2億週活躍免費用戶,在4月30日政策更新時被自動加入追蹤,官方有寄信通知
  • Plus / Enterprise訂閱戶:預設排除在追蹤範圍外
  • 未滿18歲用戶:豁免

為什麼「關掉行銷同意」還是被追蹤

這才是整起事件最惱人的地方:OpenAI把__obi歸類成「分析」cookie,不是「行銷」cookie。也就是說,就算你在同意設定裡拒絕了行銷用途,__obi照樣運作、照樣傳輸。這種分類方式游走在加州CPRA法規邊緣,也是這次報告引爆討論的核心。

怎麼自保:3個實際步驟

  • 到「設定 > Data Controls > Marketing Privacy」確認目前的追蹤狀態,即使可能擋不掉__obi,至少先關掉能關的
  • 查詢醫療、法律、財務等敏感問題時,用無痕視窗或登出狀態發問,避免綁定帳號
  • 定期清除.openai.com底下的cookie,或用瀏覽器擴充功能封鎖第三方追蹤像素

OpenAI強調對話內容本身不會分享給廣告商,這點沒錯。但問題從來不是對話內容,而是「你是誰、去過哪裡」被悄悄串起來賣給廣告主。這也不是OpenAI第一次踩線——ChatGPT.com先前已被踢爆內嵌Meta Facebook Pixel,並因此面臨集體訴訟。

好不好用,試了才知道。


🇺🇸 ChatGPT Tracking Cookie Review: Opt-Out Doesn't Stop __obi

ChatGPT's Tracking Cookie "__obi": What It Actually Does

A security research team published findings on September 20, 2026 exposing OpenAI's __obi tracking cookie — a cross-site tracking mechanism set on .openai.com with a one-year lifespan that binds your signed-in ChatGPT account to your browsing activity on other websites. Researchers privately disclosed the issue to OpenAI on September 14; the company acknowledged receipt but declined to answer questions about cookie classification or consent handling before the report went public a week later.

How __obi Works: Three Steps to Cross-Site Identification

The mechanism itself is straightforward:

  • ChatGPT generates a random identifier client-side
  • It requests a signed JWT token from OpenAI's servers, binding that identifier to your account
  • OpenAI sets the __obi cookie on .openai.com with cross-site transmission enabled

From there, any time you visit a site running OpenAI's ad tracking pixel — researchers confirmed at least 12 commercial sites including Chewy, Wayfair, HelloFresh, Coursera, and SeatGeek across 13 distinct pixel IDs — __obi gets sent back to OpenAI along with scraped data like your email, phone number, and postal code. Of 932 decoded tokens analyzed, 736 mapped directly to specific accounts; 638 of 881 pixels examined had automatic identity matching enabled.

Who's Tracked, Who Isn't

  • Free-tier users: roughly 200 million weekly active users were auto-enrolled when the policy changed on April 30, 2026, with email notification
  • Plus / Enterprise subscribers: excluded by default
  • Users under 18: exempt

Why Turning Off "Marketing" Consent Doesn't Stop It

This is the part driving the outrage: OpenAI classifies __obi as an analytics cookie, not a marketing one. That means declining marketing consent in your privacy settings does nothing to stop it — it keeps firing regardless. That classification sits right at the edge of what California's CPRA rules allow, and it's the core reason this story blew up.

How to Protect Yourself: 3 Practical Steps

  • Go to Settings > Data Controls > Marketing Privacy and turn off everything you can, even if it won't fully stop __obi
  • Use an incognito window or a logged-out session for sensitive medical, legal, or financial questions so nothing binds to your account
  • Periodically clear cookies under .openai.com, or use a browser extension to block third-party tracking pixels

OpenAI maintains — correctly — that actual chat content isn't shared with advertisers. But the real issue was never the conversation text; it's the quiet stitching-together of who you are and where you've been, sold into the same ad infrastructure. This isn't OpenAI's first privacy misstep either: ChatGPT.com was previously found to embed Meta's Facebook Pixel, which triggered a separate class-action lawsuit.

好不好用,試了才知道。

Sources / 資料來源

延伸閱讀 / Related Articles


AI 工具觀察站 — 每日精選 AI Agent 與工具趨勢
AI Tool Observer — Daily curated AI Agent & tool trends

留言

這個網誌中的熱門文章

Google Ironwood TPU v7 推理專用晶片解析:效能追平 NVIDIA、成本低 44%,AI 晶片戰爭正式開打 | Google Ironwood TPU v7 Explained: Matching NVIDIA Performance at 44% Lower Cost — The AI Chip War Heats Up

Claude Code 實測:AI 幫你寫程式到底行不行? | Claude Code Review: Can AI Really Code for You?

Cursor vs GitHub Copilot vs Claude Code:AI 程式助手大比拼 | AI Coding Assistants Compared: Cursor vs GitHub Copilot vs Claude Code