logoalt Hacker News

rvztoday at 3:48 AM4 repliesview on HN

This whole blog-post is impressive with the chain of vulnerabilities involved. However...

> OpenAI also paid us a $6,500 bounty.

?

That amount for this payout is beyond pathetic for a near $1.2T company, who just got themselves breached with a complete potential source code leak.

This is like getting close to breaching the main monorepo at Google: google3.

If this was on the black market and the leak included unreleased models and training material, it would easily be worth tens of millions. Even reporting crypto smart contract flaw pay way more than that on average of $100k - $10M.

Come on.


Replies

muglugtoday at 4:03 AM

My guess is that OpenAI has done a lot more to prevent exfil of their model weights than the codebase of their main web app and client.

fwlrtoday at 5:17 AM

Perhaps the exploit was not as large or dangerous as the team says it is.

show 1 reply
agentwangtoday at 8:08 AM

[dead]

sudo_cowsaytoday at 3:54 AM

The unfortunate truth of doing the right thing. Also, correct me if I'm wrong but there are too many bad things out there and companies can't give 1 million bounty for stuff like that. I'm sure they could but in the long run, wouldn't it be unsustainable?

show 3 replies