‹ BackHN Continuity

Thread

A heap overflow and SSO misconfiguration to compromise OpenAI internal repos

491 points · 208 comments · Handy-Man

  1. kerenskiy · · focus · HN ↗
    $6 500 bounty for this is a joke. The black market price would be smth like $6 500 000 or more
    1. tptacek · · focus · HN ↗
      There is probably no black market for this at all.

      <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=43025038">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=43025038

      1. parhamn · · focus · HN ↗
        &gt; Valuations for server-side vulnerabilities are low, because vendors don&#x27;t compete for them.

        Why don&#x27;t they?

        1. devmor · · focus · HN ↗
          Because as soon as they are patched, they are worthless.

          People pay for vulnerabilities because they want to exploit them - if there’s a limited window, there’s limited demand.

          Even if there’s something worth a lot behind the exploit, a potential criminal would be better off obtaining whatever that is and selling it instead.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.