‹ BackHN Continuity

Thread

A heap overflow and SSO misconfiguration to compromise OpenAI internal repos

491 points · 208 comments · Handy-Man

  1. nullbio · · focus · HN ↗
    This is legal to do without written permission? $6,500 for this feels like peanuts. The potential reach of such a hack is insane, especially with access to Github. OAI is lucky they were ethical and didn't sell this for several hundred thousand to a malicious third party.
    1. VectorLock · · focus · HN ↗
      $3500 when you consider they returned $3000 of that back to OpenAI in the form of burnt tokens.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.