A heap overflow and SSO misconfiguration to compromise OpenAI internal repos
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
A heap overflow and SSO misconfiguration to compromise OpenAI internal repos
Unofficial Hacker News client; not affiliated with Y Combinator.
kerenskiy · · focus · HN ↗
sudo_cowsay · · focus · HN ↗
kdkdkwkdjej · · focus · HN ↗
tptacek · · focus · HN ↗
<a href="https://news.ycombinator.com/item?id=43025038">https://news.ycombinator.com/item?id=43025038
[deleted] · · focus · HN ↗
[deleted]
parhamn · · focus · HN ↗
Why don't they?
devmor · · focus · HN ↗
People pay for vulnerabilities because they want to exploit them - if there’s a limited window, there’s limited demand.
Even if there’s something worth a lot behind the exploit, a potential criminal would be better off obtaining whatever that is and selling it instead.
kerenskiy · · focus · HN ↗
tptacek · · focus · HN ↗
lbrandy · · focus · HN ↗
Mohansrk · · focus · HN ↗
akerl_ · · focus · HN ↗
loveparade · · focus · HN ↗
samtheprogram · · focus · HN ↗
I don't think the other commenters mentioning how server-side vulnerabilities aren't as lucrative in the black market are making that connection.
fancythat · · focus · HN ↗