‹ BackHN Continuity

Thread

A heap overflow and SSO misconfiguration to compromise OpenAI internal repos

491 points · 208 comments · Handy-Man

  1. kerenskiy · · focus · HN ↗
    $6 500 bounty for this is a joke. The black market price would be smth like $6 500 000 or more
    1. samtheprogram · · focus · HN ↗
      Per the article, that's the price OpenAI is willing to pay for an exploit that covers any account or integration one connects to their OpenAI account. Let that sink in.

      I don't think the other commenters mentioning how server-side vulnerabilities aren't as lucrative in the black market are making that connection.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.