Remember What They Took From You
- Taskup confirmation by Latitude PR
- Latitude's admission of the April data breach
- anon on Taskup paid to review flagged stories
- folder of screenshots from anon
- features retired
- Latitude works with AI21
- implemented filters to protect one dimensional text children from abuse. But because they have never heard of RegEx, it's ineffective at best and completely breaks normal stories at worst: Update to Our Community - April 27 / web archive / archive.md
- Know the filter (may be outdated)
- proudly announced that they'll add more to their filters in the future.
- refused to listen to community concerns. "This is what it means to take a stand 🤷♂️": A selection of interesting quotes from our dearest Alan
- have known about a vulnerability that leaked user content alongside their user names for at least a month, but chose not to inform their users: AID Adventure Vulnerability Report released on the 26th of April
Notice: Following responsible disclosure procedures, the issues here have been brought up to the developers and have been fixed before this report was published. Similarly, all private data collected has been deleted.
On April 18th, I discovered a vulnerability in the AI Dungeon GraphQL API that allowed unpublished adventures, unpublished scenarios, and unpublished posts to be leaked. These resources could be read in bulk, at a rate of approximately 1000 requests per minute. Unfortunately, this is, in fact, the second time I have discovered this exact vulnerability. The first time, the issue was reported and fixed, but after finding it again, I can see that simply reporting the issue was a mistake.
- realized this won't just blow over in a couple days and entered radio silence.
- continued adding words to the filter, triggering more and more false positives.
- deleted a community suggestion on their feedback forums which asked them to only moderate public stories.
- removed their social media links from the play.aidungeon.io site: r/AIDungeon: Why fix when you can remove - The links for Discord / Reddit / Blog / Twitter have been EXPUNGED
- disowned their official Discord server, changing the welcome message from official to unofficial literally as people were discussing its legitimacy. Some moderator was lurking in the discussion, some guy posted a link to the server's welcome message as proof that the server is official and not 5 minutes later it was edited to say unofficial.
- cancelled all live streams until the 7th of July.
- banned, without warning, AI Dungeon accounts using scripts that interfere with filtered words. Users received silence from customer support regarding this matter.
- continued pushing mini updates that either do basically nothing or break things. May 17, first actual game update since the incident. World Info overhauled; now buggy and unstable. Pointless UI updates followed, most likely to look busy.
There was a bug that made WI entries invisible. Anon with alt accounts on different display themes discovered that entries only show up if you set your theme to BLACK, DARK, or LIGHT.
- finetuned their AI models with content violating their own policies: Presentation of select portions of the data set used to fine-tune both the GPT-2 and GPT-3 models of Oasis Tech, Inc.'s (doing business as Latitude) text adventure game, AI Dungeon. This document cites official Latitude content not suitable for minors.
Latitude claims that AI Dungeon users were generating "content that may promote the sexual exploitation of minors." In response to that claim, this document presents the publicly available fine-tuning data used to train AI Dungeon’s model, i.e., Classic, and AI Dungeon 2’s models, i.e., Griffin and Dragon. Closer examination reveals that Latitude fine-tuned its AI models on content the company now filters and ban users or locks user progress for the AI generating said content.
- had users' stories read by outsourced workers: Now CONFIRMED
anon's post about being paid to review flagged stories through Taskup.ai
r/AIDungeon: Latitude is paying random strangers on a crowdsourcing platform money to read your stories and police them for no-no words.
Video proof of him navigating the website
I remember reading this story from a user made Scenario published on AID's Explore, when it was still up.
"The information that the content being sent for crowdsourced moderation is FAR FAR broader than what's caught by Latitude's CP filter, it seems to be basically all smut, and anything that looks like it could possibly be smut." "also non-smut" anons added.
An AID Discord server moderator asked Latitude developer Avi about this.
They still haven't said anything about the questionable training data they used.
The thread called him larpanon because at first they thought he was LARPing.
A different anon claimed he can access a Taskup database where the stories for review are stored.
Taskup went down for about a day until 05/30/21 00:01:56, when another anon noticed it was back up. Time in the screenshot is in UTC+2. We don't actually know if the outage had anything to do with DBanon accessing their data.
Larpanon said he got shadowbanned: https://arch.b4k.co/vg/thread/337384257/#337447483
Larpanon screenshots & DBanon database matches:
MEGA .nz compilation
^ is organized and has gallery view.
Catbox backup (link starts download)
imgur backup - LarpAnon Part1
imgur backup - LarpAnon/TaskupAnon part 2
OCR of the screenshots for easy Ctrl+F searching
Content in the database DBanon accessed matched with users' stories.
View these image links in order.
Your captor 1 (DBanon match)
Your captor 2
Your captor 3
Your captor 4 (user confirmation)
Cumsnake 1 (DBanon match)
Cumsnake 4 (user confirmation)
Cumsnake 5 (user confirmation)
r/AIDungeon: […] the evidence of negligence to their customer-base is just insurmountable.
- started using an automated suspension system: Screenshot of the changelog
their updates page: https://play.aidungeon.io/main/allUpdates
We've Been Hard at Work! Here's What's New Since You Last Logged In:
- Suspension System: As the next evolution of our safety strategy, we will begin to automatically suspend the accounts of the 5% of users who most frequently violate our content policies. The first suspension lasts 24 hours and subsequent violations will trigger a 7-day suspension. All suspensions will be reviewed manually by human moderators to ensure accuracy and remove incorrect suspensions. Most users have still never triggered the safety filter a single time, so we expect that most users will be similarly unaffected by this change.
- Anonymous 05/30/21(Sun)23:36:14 No.337518757
- r/AIDungeon: Asked a kid how babies are made. She said storks bring them. Boom, got a pedo-ban.
- septupled-down on invasive policies: Moderation Clarification to the Community - June 8 / web archive / archive.md
In this update, we address questions we’ve received about moderation policies and privacy, and introduce our new Content Policy with specific guidelines about what content is allowed on AI Dungeon.
Our reviews of flagged content are logged, including the reviewer and the decision they made, so Latitude knows which employee or legal team member took a particular moderation action.
- released NuExplore, then killed it. Only the popular/featured scenarios screen remains: Explore is temporarily unavailable.
- Explore is missing.
- Look at the new home page with the UI they planned to give NuExplore.
- Look at it.
- screenshot of the changelog
- New Explore Page: We know you have all been waiting eagerly for the return of the Explore page, and we thank you for your patience! Beginning now, some users will see a test of our new home screen / explore page experience. We welcome constructive feedback on the new page to firstname.lastname@example.org. Please begin the subject line with “Explore:”.
For now, the new Explore experience will include a limited selection of scenarios to choose from, but this selection will be expanded very soon. Keep an eye out for more updates!
- had a glitch with their feature suggestion site: screenshot of the changelog
- Feature Suggestion Fix: Due to a glitch with our feature suggestion system, Ideas reviewed by the admins have not been becoming visible since May 3. You can now see and vote for the hundreds of great new ideas submitted by the community after May 3 as expected on features.aidungeon.io.
They use a site provider called Aha! for their idea management.
- updated their filters.
- updated their filters again: Another Filter Update - Jul. 28
the April 18 data breach after five months: https://latitude.io/blog/data-incident-april-2021
We recognize that scaling the business necessitates a continually evolving strategy that remains devoted to user security and privacy. Latitude is committed to that goal. We will work hard to protect our community.
Thank you for your continued membership in our community. Emails are being sent to users whose information was involved.
- deleted over 21,000,000 duplicate WI entries.
- shifted to the Walls approach: The Walls Approach - Sept. 30
that OpenAI was sending AID stories to Taskup for review: Updated related to Taskup Questions u/Ryan_Latitude on r/AIDungeon / archive.md
Earlier this year, on May 27, we were made aware that around 100 text clippings from AI Dungeon stories had been posted to 4chan. We immediately launched an investigation into the incident, determining the source to be a company named Taskup. AI Dungeon does not, and did not, use Taskup or any other contractor for moderation. We reached out to our AI vendor, OpenAI, to determine if they were aware of Taskup.
OpenAI informed us that they had conducted an investigation and determined that their data labeling vendor was using Taskup. They found that a single contractor, labeling as part of OpenAI's effort to identify textual sexual content involving children that came through AI Dungeon, posted parts of stories to 4chan. OpenAI informed us they have stopped sending samples to this vendor.
- decided to work with AI21.
- retired features.
The kicker is that in addition to the time/attention it takes to support these features whenever we make other changes, it currently costs over $6k/month to run the models that handle death/quest detection.