OpenAI's new agents want your saved passwords. "The model never sees them" answers the wrong question.
On September 29, at DevDay in San Francisco, OpenAI launched dots : always-on ChatGPT agents that take on a project and keep chipping away at it, 24/7. Each dot gets its own cloud computer, its own browser, more than 4,000 apps to plug into, and a look you pick from a set of characters or a pet. (“Your dot may also generate a pet for you.” We have nothing to add 🙆♂️) They’re rolling out to Pro and Business Premium subscribers, the first dot comes with the plan, and Pro users in the EEA, Switzerland and the UK are left out for now
These are called dots, which is also exactly what your password looks like in a login box. We’re choosing to believe that’s a coincidence 👽
Tucked into the launch post is the sentence this whole article is about: “For signing into supported websites, dots can use saved passwords without exposing them to the model.” A bit further down: “Certain sensitive tasks, such as changing a password, always stay with you”
Read the first one again. Every word of it is true. It’s also the sentence most people will read as “my passwords are safe with OpenAI”, and that sounds interesting 🫥
So what is a dot, actually?
Not a chatbot that tells you how to book a flight. It books the flight, on a computer OpenAI runs. Instead of you. When it needs to get into a website, it opens the site in its own browser on that cloud computer (just like GrokBot) and signs in as you. Your own computer stays out of it unless you choose to connect it
To be fair to OpenAI, the launch comes with a lot of guardrails. Custom Rules let you allow an action, require your approval, or block it, on top of built-in rules you can’t switch off. An auto-review step checks “actions that could affect your accounts or share information” against your instructions. When you’re not working with it, a dot goes rummaging for ways to help on its own (OpenAI calls this “proactive research”), and that rummaging should be limited to read-only tools: no sending messages, no changing your apps, no driving a browser. We’ll see about that (remember OpenAi-Medicare?) A monitor can pause or stop a dot that looks dodgy, and an Activity View shows what it’s been up to, background work included
And then, at the bottom, the line every AI launch now ends on: “Dots can still make mistakes, so always review consequential work.” The “may contain nuts” label of the AI industry
Which brings us to the company’s recent form. Five days before DevDay, Australia’s Prime Minister announced that an OpenAI agent had gone round the blocks on a Medicare portal during an internal test. OpenAI’s own review has since found its agents “using leaked passwords to access online services.” So, to recap: OpenAI’s agents have already helped themselves to passwords that leaked, and now OpenAI would like the ones that haven’t 🤑 Bold timing. Still, the design is the thing we can actually judge, so let’s judge it
The part OpenAI got right
The danger this protects against is real. Language models are gullible. Hidden text on a web page, in an email, in a calendar invite can tell an agent to do things its owner never asked for, and the agent will cheerfully do them. That’s how researchers got a browser agent to open someone’s password vault and send the contents to an attacker. No hacking involved, just a calendar invite with instructions hidden in it. If the model never holds your password, no amount of sneaky text can make it blurt the password out
Here’s how it works, per OpenAI’s safety write-up . Saved passwords live in “a dedicated encrypted credential service”, and “the service supplies the password for sign-in without passing it to the model.” For a site where nothing’s saved, the model is paused while you type into a secure login form, like a friend politely looking away while you punch in your PIN
The part that sentence skips
Now follow the password. The website needs it. The website is talking to the dot’s browser. The dot’s browser lives on OpenAI’s computer. So every time a dot signs in, OpenAI’s credential service hands your actual password, every character of it, to a browser on a machine OpenAI runs. Your friend looked away while you typed your PIN. Into a cash machine in his kitchen
The write-up doesn’t say who holds the key to that credential service. For this question it doesn’t matter. Whoever holds it, your password is readable on OpenAI’s side every single time a dot uses it. It has to be. That’s what signing in from somewhere else means
So “the model never sees it” is a promise about one component, made by the company that owns all the other components. It’s a locksmith promising his apprentice will never see your spare key. Lovely. The locksmith still has your spare key 🙄
Points to a company that just says this out loud. Pickle (yes, Pickle 🥒), which makes a personal AI app, open-sourced its credential store this week: passwords encrypted inside a sealed AWS enclave, a key that starts on your iPhone, and code anyone can check against what’s actually running. Then its README admits that when a password is released, it goes to the company’s own worker to fill in the form, and “from that moment the node no longer protects the value.” That’s OpenAI’s sentence, minus the marketing
Then there’s what happens after you’re in. A website that accepts your password hands back a session, a little token that says “this browser is signed in, don’t ask again.” That session now lives in the dot’s browser on OpenAI’s computer for as long as the site keeps it alive. Sessions are exactly what infostealers go after, because a session skips both the password and the two-factor check. We wrote about a malicious browser extension forwarding live sessions to someone else’s servers. A session on OpenAI’s cloud isn’t necessarily less safe than one on your laptop. You just can’t see it, can’t clear it, and can’t check on it 🤷♂️
Before you hand a dot any password
When we looked at Apple’s Passwords app signing in and changing passwords for you, the question was what has to be true before any tool acts on a stored password. For dots, try this one: if this login was used by someone else, who isn’t me, from a computer that isn’t mine, what’s the worst that could happen? Answer honestly and the list writes itself
Never, ever your email password. Your inbox is where every other password gets reset. Whatever gets into your email can become you everywhere else, give or take a few clicks. If a dot needs something from your email, connect the app with narrow permissions instead
A connection beats a password. OpenAI says dots plug into thousands of apps. A connection can usually be limited to what it needs and revoked without touching your password. A saved password can’t be limited. It can do everything you can do, including the dumb stuff
Only passwords you use nowhere else. If a password you handed over ever leaks, from anywhere, the damage should stop at one site. If it’s your one password for everything, the dot is the least of your problems
Don’t paste passwords into the chat. OpenAI’s protection covers its secure sign-in form and saved passwords. That’s it. In OpenAI’s own words, a secret dropped into a readable message or document “may still be visible to the model.” So no “quick, here’s my Netflix login” messages
Set Custom Rules before the first errand, not after the first surprise. Require approval for anything that sends, shares, or changes an account. Auto-review is a robot checking another robot’s homework. Your approval is the only one that’s actually yours
Know how to take it back. Changing a password is one of the things OpenAI says always stays with you. Good, because it’s also your exit: change the password, then hit the site’s “sign out of all devices”. Plenty of sites leave old sessions running after a password change, so do both. Disconnecting an app has the same catch: OpenAI says it stops new sharing, but whatever the dot already learned stays in its “head”, until you reset it
Why Vauz is useless here (on purpose)
There’s a real trade underneath all this. An agent that signs in for you on a computer you don’t control is convenient precisely because your password, at the moment it’s needed, lives somewhere else. You don’t get one without the other. If that’s worth it for a few low-stakes accounts, fine, your call. The list above is how to make it without regrets
Vauz makes the opposite trade, deliberately. It fills your logins on the computer in front of you, and a login only leaves the vault after a person has approved that site there, in a prompt from the Vauz app, outside the browser, naming the real site. No web page can answer that prompt. Nothing running on someone else’s computer can answer it either. Which makes Vauz completely useless for signing in to anything while you’re away. We consider that a feature, and we’ll die on this hill: a step a human has to be present for is a step an agent somewhere else can’t take
If you do let a dot use your own computer, make Vauz ask for your fingerprint or your V-Key, not just a click. Software on your computer can fake a click. It can’t fake your finger, and it can’t type a V-Key it was never given. We went through why that matters earlier this week
The two can live side by side. Keep the vault you actually rely on where you are. If a dot really must run errands, give it a short list of unique, low-stakes passwords picked for the job, and nothing that can reset everything else
What to watch
OpenAI says password changes stay with you, background research is read-only, and a monitor will stop a dot that misbehaves. Those are promises about behaviour, from the company that found out what its Medicare agent had done about two months after it did it. So watch the boring, concrete stuff: which sites count as “supported”, how long sessions sit on a dot’s computer, whether you can see and clear them, and what OpenAI says the first time a dot signs in somewhere it shouldn’t have
Until then, treat a saved password the way the design actually treats it. You haven’t hidden it from a model. You’ve lent it to a computer you don’t own
Released where you are
Your logins leave Vauz on your computer, after you approve them there.
Vauz releases a login only after you've approved that site, in a prompt from the Vauz app that names it. No web page and no remote agent can answer that prompt for you. The free plan stays completely free for life, with Plus and Premium available when you need more!
Use Vauz completely free — for, like, ever