45 minutes ago · Tech · hide · 0 comments

A recent post on Hacking OpenAI and a bug bounty of $6,500 reminded me of an old problem. A security company was able to hack into private OpenAI repositories, but only got a small bounty. A company with a valuation of $852 billion paid a few pennies to researchers. In comparison, such data could be sold for hundreds of thousands on the black market. For those who don't know, a bug bounty program is a way for companies to pay white-hat hackers (security researchers) to find vulnerabilities in their services and software. Bug bounties allow researchers to perform security research in a legal way and get paid for it. The hack was initiated through a hosted Discourse forum, but that forum was out of the scope of OpenAI's bug bounty program. In bug bounty programs, there is usually a list of services the company wants to be tested and the rest of the services do not receive any bounty. In the case of the OpenAI hack, accessing the private data (from repositories) was in scope,[......]

No comments yet. Log in to reply on the Fediverse. Comments will appear here.