Microsoft Threat Intelligence Podcast

Whisper Leak: How Threat Actors Can See What You Talk to AI About


Listen Later

In this episode of the Microsoft Threat Intelligence Podcast, host⁠ ⁠⁠Sherrod DeGrippo is joined by security researchers Geoff McDonald and JBO to discuss Whisper Leak, new research showing that encrypted AI traffic can still unintentionally reveal what a user is asking about through patterns in packet size and timing.  

They explain how LLM token streaming enables this kind of side-channel attack, why even well-encrypted conversations can be classified for sensitive topics, and what this means for privacy, national-level surveillance risks, and secure product design. The conversation also walks through how the study was conducted, what patterns emerged across different AI models, and the steps developers should take to mitigate these risks. 


In this episode you’ll learn:      

  • Why packet sizes and timing patterns reveal more information than most users realize 

    • How user-experience choices like showing streamed text create a larger attack surface 

      • The difference between classic timing attacks and the new risks uncovered in Whisper Leak 

         

        Resources:  

        • View JBO on LinkedIn 

          • View Geoff McDonald on LinkedIn   

            • View Sherrod DeGrippo on LinkedIn  

               Learn more about Whisper Leak 

               

               Related Microsoft Podcasts:                   

              • Afternoon Cyber Tea with Ann Johnson 

                • The BlueHat Podcast 

                  • Uncovering Hidden Risks     

                     

                    Discover and follow other Microsoft podcasts at microsoft.com/podcasts  

                     

                    Get the latest threat intelligence insights and guidance at Microsoft Security Insider 

                     

                     

                    The Microsoft Threat Intelligence Podcast is produced by Microsoft, Hangar Studios and distributed as part of N2K media network. 

                    ...more
                    View all episodesView all episodes
                    Download on the App Store

                    Microsoft Threat Intelligence PodcastBy Microsoft

                    • 5
                    • 5
                    • 5
                    • 5
                    • 5

                    5

                    22 ratings


                    More shows like Microsoft Threat Intelligence Podcast

                    View all
                    Hacked by Hacked

                    Hacked

                    187 Listeners

                    Security Now (Audio) by TWiT

                    Security Now (Audio)

                    2,005 Listeners

                    The Talk Show With John Gruber by Daring Fireball / John Gruber

                    The Talk Show With John Gruber

                    3,143 Listeners

                    Risky Business by Patrick Gray

                    Risky Business

                    372 Listeners

                    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

                    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

                    652 Listeners

                    CyberWire Daily by N2K Networks

                    CyberWire Daily

                    1,019 Listeners

                    Smashing Security by Graham Cluley

                    Smashing Security

                    319 Listeners

                    Click Here by Recorded Future News

                    Click Here

                    417 Listeners

                    Darknet Diaries by Jack Rhysider

                    Darknet Diaries

                    8,063 Listeners

                    Cybersecurity Today by Jim Love

                    Cybersecurity Today

                    178 Listeners

                    Hacking Humans by N2K Networks

                    Hacking Humans

                    315 Listeners

                    CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

                    CISO Series Podcast

                    188 Listeners

                    Cybersecurity Headlines by CISO Series

                    Cybersecurity Headlines

                    139 Listeners

                    Cyber Hack by BBC World Service

                    Cyber Hack

                    1,605 Listeners

                    Risky Bulletin by risky.biz

                    Risky Bulletin

                    44 Listeners