‹ BackHN Continuity

Thread

A heap overflow and SSO misconfiguration to compromise OpenAI internal repos

491 points · 208 comments · Handy-Man

  1. nullbio · · focus · HN ↗
    This is legal to do without written permission? $6,500 for this feels like peanuts. The potential reach of such a hack is insane, especially with access to Github. OAI is lucky they were ethical and didn't sell this for several hundred thousand to a malicious third party.
    1. r00bot · · focus · HN ↗
      It depends who you're hacking, where they're based, where you're based, and what you do. If you're extremely careful not to break any of the rules it can be completely legal, as it was in this case. Many jurisdictions make it completely illegal. I agree that $6,500 is a pittance.
      1. NonHyloMorph · · focus · HN ↗
        And so they told the world ¯\_(ツ)_/¯
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.