‹ BackHN Continuity

Thread

A heap overflow and SSO misconfiguration to compromise OpenAI internal repos

491 points · 208 comments · Handy-Man

  1. nullbio · · focus · HN ↗
    This is legal to do without written permission? $6,500 for this feels like peanuts. The potential reach of such a hack is insane, especially with access to Github. OAI is lucky they were ethical and didn't sell this for several hundred thousand to a malicious third party.
    1. monster_truck · · focus · HN ↗
      If you read the article, you will see this was within the acceptable scope listed on OAI's bug bounty program.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.