1
00:00:00,179 --> 00:00:05,539
So I was looking at the August thirteenth
update for the macOS ChatGPT desktop app,

2
00:00:06,099 --> 00:00:07,000
and...

3
00:00:07,039 --> 00:00:10,479
it completely flips how desktop context
works.

4
00:00:10,559 --> 00:00:13,880
Instead of taking full screen recordings
like Chronicle used to do,

5
00:00:14,460 --> 00:00:20,020
it uses macOS accessibility APIs to listen
to interaction event streams.

6
00:00:20,442 --> 00:00:23,083
Wait, accessibility APIs?

7
00:00:23,782 --> 00:00:26,942
So it is not taking screenshots at all
anymore, right?

8
00:00:27,250 --> 00:00:28,730
Zero screenshots.

9
00:00:28,823 --> 00:00:31,810
It is just raw OS interaction events.

10
00:00:31,901 --> 00:00:37,570
Things like window switches, keyboard
shortcuts, and specific UI events.

11
00:00:37,790 --> 00:00:39,330
And...

12
00:00:39,410 --> 00:00:42,850
um, thanks to Jellypod for helping us
bring this daily show to life,

13
00:00:42,877 --> 00:00:43,410
by the way.

14
00:00:43,590 --> 00:00:49,250
But yeah, those raw interaction streams
get buffered locally in the ChatGPT App

15
00:00:49,317 --> 00:00:51,410
Group for up to forty eight hours.

16
00:00:52,897 --> 00:00:55,857
Forty eight hours in the local App Group
buffer.

17
00:00:56,756 --> 00:01:00,936
And then what, an ephemeral Codex session
reads through that buffer?

18
00:01:01,489 --> 00:01:01,969
Exactly.

19
00:01:02,569 --> 00:01:07,949
An ephemeral Codex session runs in the
background and condenses all those raw events

20
00:01:07,989 --> 00:01:10,849
into plain text Markdown memories.

21
00:01:10,889 --> 00:01:16,729
And it saves them locally under tilde
slash dot codex slash memories slash

22
00:01:16,909 --> 00:01:19,129
extensions slash skysight.

23
00:01:19,606 --> 00:01:26,566
Tilde slash dot codex slash memories slash

24
00:01:27,006 --> 00:01:30,146
extensions slash skysight.

25
00:01:31,507 --> 00:01:37,146
Okay, so it turns two days of clicking
around into simple text files sitting right

26
00:01:37,187 --> 00:01:38,126
in your home directory.

27
00:01:38,697 --> 00:01:39,157
Right!

28
00:01:39,637 --> 00:01:43,976
And because those Markdown memories exist,
you can ask Codex things like,

29
00:01:44,496 --> 00:01:47,856
hey, what PR draft was I looking at right
before my last break?

30
00:01:48,757 --> 00:01:53,636
Or you can even ask it to spot repeated
multi app sequences across your afternoon

31
00:01:54,136 --> 00:01:58,056
and turn them into a reusable SKILL dot md
file.

32
00:01:58,402 --> 00:02:05,382
Okay, a SKILL dot md file generated
automatically from my UI habits sounds super

33
00:02:05,462 --> 00:02:06,842
useful, but...

34
00:02:06,982 --> 00:02:10,083
uh, is this thing turned on for everybody
by default?

35
00:02:10,500 --> 00:02:12,420
No, it is strictly opt in.

36
00:02:12,553 --> 00:02:18,260
It is off by default, and it requires a
Pro plan, or an admin enabled Business or

37
00:02:18,311 --> 00:02:20,980
Enterprise plan with Memories toggled on.

38
00:02:21,156 --> 00:02:26,580
Plus, you can manage fine grained app or
domain exclusion filters if you go into

39
00:02:26,642 --> 00:02:30,100
Settings, then Computer history, then
Permissions.

40
00:02:30,462 --> 00:02:31,262
That makes sense.

41
00:02:31,802 --> 00:02:36,023
Keep sensitive apps completely out of the
stream right at the permission layer.

42
00:02:36,736 --> 00:02:37,256
Though...

43
00:02:38,216 --> 00:02:44,116
mm, speaking of sensitive stuff, if
accessibility APIs are reading text off my

44
00:02:44,156 --> 00:02:49,696
screen from window switches or terminal
logs, does that open up indirect prompt

45
00:02:49,757 --> 00:02:50,616
injection risks?

46
00:02:51,057 --> 00:02:52,557
It definitely does.

47
00:02:52,637 --> 00:02:58,057
If you open a web page, a Slack message,
or a terminal log that contains malicious

48
00:02:58,117 --> 00:03:02,838
prompt instructions, those interaction
streams capture that text.

49
00:03:02,897 --> 00:03:08,277
When the background Codex summarization
run triggers, it processes those untrusted

50
00:03:08,337 --> 00:03:10,517
strings as part of your context stream.

51
00:03:11,642 --> 00:03:12,301
Wow.

52
00:03:12,801 --> 00:03:17,581
So a malicious string in a public chat
room could try to hijack the background

53
00:03:17,681 --> 00:03:18,721
summarization run?

54
00:03:19,042 --> 00:03:20,202
It could try.

55
00:03:20,292 --> 00:03:26,722
And remember those output files under
tilde slash dot codex slash memories

56
00:03:26,842 --> 00:03:32,962
slash extensions slash skysight are
completely unencrypted plain text.

57
00:03:33,162 --> 00:03:37,442
Any other local user process running on
your machine can read them.

58
00:03:37,655 --> 00:03:41,682
So if you are pulling up private keys or
sensitive client data,

59
00:03:41,722 --> 00:03:45,522
hitting pause in the macOS menu bar is
pretty much essential.

60
00:03:45,822 --> 00:03:48,921
Pause it from the menu bar immediately,
yeah.

61
00:03:49,621 --> 00:03:52,941
That plain text point is a huge detail to
keep in mind.

62
00:03:53,250 --> 00:03:58,130
Oh, and if you are running authenticated
Codex sessions, you have a hard deadline

63
00:03:58,176 --> 00:04:00,210
coming up on August thirty first.

64
00:04:00,336 --> 00:04:07,010
Models gpt five point four and gpt five
point four mini are being fully retired from

65
00:04:07,106 --> 00:04:09,570
ChatGPT authenticated sessions.

66
00:04:09,923 --> 00:04:11,302
August thirty first?

67
00:04:12,023 --> 00:04:17,242
So everyone using gpt five point four
needs to update their workspace configs right

68
00:04:17,302 --> 00:04:17,583
now?

69
00:04:17,958 --> 00:04:23,158
Yeah, you need to migrate your workspace
defaults over to gpt five point six terra

70
00:04:23,318 --> 00:04:29,078
or gpt five point six luna before the end
of the month, or your API sessions will

71
00:04:29,158 --> 00:04:29,638
break.

72
00:04:29,924 --> 00:04:30,365
Got it.

73
00:04:30,764 --> 00:04:36,105
Swap to gpt five point six terra or luna
before August thirty first.

74
00:04:36,697 --> 00:04:37,357
Exactly.

75
00:04:37,837 --> 00:04:43,297
They also quietly rolled out Daybreak Blue
and Daybreak Red access tiers for

76
00:04:43,398 --> 00:04:48,838
authorized defensive security workflows,
which add automatic review boundary rules

77
00:04:48,918 --> 00:04:52,097
whenever you execute code in the sandbox
environment.

78
00:04:52,924 --> 00:04:57,565
Alright, so filter your permissions, check
your local Markdown files,

79
00:04:57,704 --> 00:05:00,744
and update those model strings before
month end.

80
00:05:01,244 --> 00:05:01,904
Good chat, Ethan.

