2 ms·
This whole blog-post is impressive with the chain of vulnerabilities involved. However... > OpenAI also paid us a $6,500 bounty. ? That amount for this payou
by rvz 8d ago
This whole blog-post is impressive with the chain of vulnerabilities involved. However...
> OpenAI also paid us a $6,500 bounty.
?
That amount for this payout is beyond pathetic for a near $1.2T company, who just got themselves breached with a complete potential source code leak.
This is like getting close to breaching the main monorepo at Google: google3.
If this was on the black market and the leak included unreleased models and training material, it would easily be worth tens of millions. Even reporting crypto smart contract flaw pay way more than that on average of $100k - $10M.
Come on.
- sudo_cowsay 8d agoThe unfortunate truth of doing the right thing. Also, correct me if I'm wrong but there are too many bad things out there and companies can't give 1 million bounty for stuff like that. I'm sure they could but in the long run, wouldn't it be unsustainable?
- Shank 8d agoHow much would a nation state pay for a complete copy of OpenAI’s github repositories? I doubt there are many full chains laying around like this.
- kdkdkwkdjej 8d agoNo more unsustainable than these companies already are by default. The bounty should have been proportionate to how important and pressing the findings were.
- Barbing 8d agoIt’s an interesting bet then. Pay next to nothing every time, accept one financially-depressed researcher sale to blackhats causing tremendous business disruption every n years. Cheaper than honest payouts to [keep] researchers [honest]? Keep paying chump change. (Booo)
- muglug 8d agoMy guess is that OpenAI has done a lot more to prevent exfil of their model weights than the codebase of their main web app and client.
- fwlr 8d agoPerhaps the exploit was not as large or dangerous as the team says it is.
- redox99 8d agoIt's a monorepo and they're at over 1 million PRs. There's surely some juicy stuff there.
- agentwang 8d ago[dead]