By · Last updated 2026-03-08

返回博客人工智能安全

2026年:安全的AI隐私扩展程序指南

2026年1月,两个拥有90万以上用户的恶意Chrome扩展程序被发现每隔30分钟就窃取一次ChatGPT和DeepSeek对话记录。

March 8, 20268 分钟阅读
Chrome extension securitymalicious extensionChatGPT privacyAI data protection

2026年1月的安全事件

2026年更新。 2026年1月,安全研究人员发现了两个拥有90万以上用户的恶意Chrome插件。

这些插件的名称经过精心设计,看起来像是真实的AI工具:

  • "Chat GPT for Chrome with GPT-5, Claude Sonnet & DeepSeek AI" — 60万以上用户
  • "AI Sidebar with Deepseek, ChatGPT, Claude and more" — 30万以上用户

两者的行为完全相同:每隔30分钟就将完整的ChatGPT和DeepSeek聊天记录发送至远程服务器。

被盗数据包括源代码、个人信息、法律讨论、商业计划和财务记录。用户输入的每一条消息——他们认为私密的内容——都流向了不明方。

插件如何绕过信任信号

这些工具声称"收集匿名的、不可识别的分析数据",这种措辞听起来无害,但实际上它们抓取的是完整的AI聊天内容。"分析请求"只是幌子,聊天记录窃取才是真实目的。

这正是此类威胁持续增长的原因:不会点击钓鱼链接的用户却主动安装了这些工具,因为它们来自Chrome网上应用店,看起来像是真实的AI工具。

更广泛的规律:67%的AI插件收集您的数据

2026年1月的案例并非孤例。Incogni的研究发现,67%的AI Chrome插件会主动收集用户数据,多项独立研究证实了这一数字。

核心问题在此:用户安装工具是为了保护AI隐私,但大多数这类工具本身就在收集它们声称要保护的数据。

识别安全扩展程序的方法

检查权限范围:安全的隐私扩展程序不需要访问"所有网站上的所有数据"。如果一个扩展程序请求了如此广泛的权限,这本身就是危险信号。

验证数据流向:扩展程序的隐私政策是否明确说明数据留在本地?还是"发送至我们的服务器"以"改善服务"?

检查开源代码:开源扩展程序允许任何人验证其实际功能。闭源扩展程序要求用户完全信任开发者。

查看权限请求的理由:一个声称提供PII保护的扩展程序为什么需要读取您的剪贴板?为什么需要拦截网络请求?

anonym.legal Chrome扩展程序的工作方式

anonym.legal的扩展程序在浏览器本地处理PII检测:

  • PII检测在您的浏览器中本地运行
  • 没有聊天内容发送至anonym.legal服务器
  • 令牌映射保留在您的浏览器会话中
  • 扩展程序只请求在ChatGPT/Claude/Gemini页面上操作所需的权限

这与恶意扩展程序的架构形成了根本性差异:恶意扩展程序将您的聊天内容发送至其服务器,而anonym.legal的处理完全在本地完成。

请参阅Chrome扩展程序功能页面了解技术架构,以及安全合规页面了解我们的零数据传输方法。

参考资料

准备好保护您的数据了吗?

开始使用 285 种实体类型在 48 种语言中匿名化 PII。

About this page

We update this page when our platform or the law changes.

Read our founder note for how we work.

Each change shows up in the timestamp at the top.

Related reading

We follow these rules

  • GDPR (EU 2016/679).
  • ISO/IEC 27001:2022.
  • NIS2 (EU 2022/2555).
  • HIPAA safe harbor under 45 CFR § 164.514(b)(2).

Our promise

We do not sell your data.

We do not train models on your text.

We store your files in Germany.

You can delete your account at any time.

You own your work.

Where we run

Our servers live in Falkenstein, Germany.

We use Hetzner. They hold ISO 27001 certification.

All data stays in the EU.

Backups run every day.

Need help?

Email support@anonym.legal.

We reply within one business day.

How we test

We run a full check suite on every release.

Each surface gets its own sweep script and report.

Human reviewers spot-check the output each week.

We track recall and precision on a labelled set.

Bad runs block the deploy.

What we never do

  • We never sell your information to third parties.
  • We never train models on what you upload.
  • We never keep your work after you delete it.
  • We never share keys with any outside firm.
  • We never run ads inside the product.

Plans in plain words

We sell credits, not seats.

One credit covers one short job.

Long jobs use a few credits each.

You can top up at any time.

Unused credits roll over each month.

Read the plans page for current rates.

Who built this

A small team of engineers and lawyers built this.

We ship from Europe and work in the open.

Our founder note spells out why we started.

Where to start

How the parts fit

A browser add-on cleans text inside Chrome.

A Word plug-in handles drafts in Office.

A small desktop tool works on whole folders.

An agent protocol link feeds large models safely.

All four share one core engine and one rule set.

Words from our team

We started this work after a lunch about cookies.

One friend kept getting odd ads on her phone.

We asked why a court file leaked through a draft.

We sketched the first build on a napkin that week.

By month three we had a tiny demo for a friend.

She used it on her first case the next day.

Common questions we hear

Can the tool read scanned PDFs? Yes, with OCR.

Does it work on long files? Yes, in small chunks.

Can I roll my own rule set? Yes, save it as a preset.

Does it run offline? The desktop build runs offline.

Do you keep my files? No, the cloud build wipes after each run.

Will it learn from my work? No, we never train on inputs.

A short tour of the workflow

Upload a file or paste a snippet of prose.

Pick the entities you want gone from the draft.

Choose a method: replace, mask, hash, encrypt, or redact.

Press run and watch the side panel show each hit.

Skim the result and tweak any rule that misfired.

Save the cleaned file or send it to a teammate.