‹ BackHN Continuity

Thread

A heap overflow and SSO misconfiguration to compromise OpenAI internal repos

491 points · 208 comments · Handy-Man

  1. oxi113 · · focus · HN ↗
    > Since people can connect various services to Codex and ChatGPT, the scope of what we could theoretically access was huge, including GitHub, Slack and emails.

    That's why I'm always sceptical about using the AI for such things! Less surface idea and isolation is always good for the security.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.