A recent post by @j4ck.xyz on Bluesky has brought to light a significant privacy concern regarding Microsoft Copilot. According to the post, the AI assistant can accurately report a user's location, even when using an incognito browser, not being signed into a Microsoft account, and without granting explicit location permissions.
This raises serious questions about how Microsoft is collecting and using user data. The fact that Copilot can bypass these common privacy-enhancing measures is alarming and suggests that Microsoft may be using other, less transparent methods to determine a user's location. This could include analyzing IP addresses, Wi-Fi networks, or other device information.
This is a clear breach of user trust. Users have a right to expect that their privacy will be respected, especially when they are taking steps to protect it. Microsoft's actions in this case are a clear violation of that trust.
For users who are concerned about their privacy, I recommend the following:
Be mindful of the information you share with AI assistants. Even if you are using a privacy-enhancing browser, it is still possible for AI assistants to collect data about you. Use a VPN. A VPN can help to mask your IP address and make it more difficult for companies to track your location.
- Review your privacy settings. Make sure you are comfortable with the privacy settings on all of your devices and accounts.
I will continue to monitor this situation and will provide updates as more information becomes available.