‹ BackHN Continuity

Thread

A heap overflow and SSO misconfiguration to compromise OpenAI internal repos

491 points · 208 comments · Handy-Man

  1. rvz · · focus · HN ↗
    This whole blog-post is impressive with the chain of vulnerabilities involved. However...

    > OpenAI also paid us a $6,500 bounty.

    ?

    That amount for this payout is beyond pathetic for a near $1.2T company, who just got themselves breached with a complete potential source code leak.

    This is like getting close to breaching the main monorepo at Google: google3.

    If this was on the black market and the leak included unreleased models and training material, it would easily be worth tens of millions. Even reporting crypto smart contract flaw pay way more than that on average of $100k - $10M.

    Come on.

    1. fwlr · · focus · HN ↗
      Perhaps the exploit was not as large or dangerous as the team says it is.
      1. redox99 · · focus · HN ↗
        It's a monorepo and they're at over 1 million PRs. There's surely some juicy stuff there.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.