this post was submitted on 01 Oct 2026
241 points (98.0% liked)
Technology
88390 readers
3242 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
This doesn't seem that bad to be honest. Disclosing they the access happened and what vulnerability allowed it to happen is a responsible course of action.
I'm not sure why you are getting down voted so much instead of actually engaging with your post. I think you are right about that the disclosing is the right thing to do, but i believe that the problem people have with this whole AI hacking and disclosing is the intent behind the hacking. A white hat hacker has a clear intend to help discover and responsibly disclose the issue, maybe even for a bounty, giving an indirect permission to white hat hacking. On the other hand, AI does not have a clear intend behind the hacking. Very often it's accidental and done irresponsibly like a "woopsie doozy, sorry we just broke in, we didn't mean to, and we are not really sure what files were accessed but pinky swear we think we did no harm 🫣🤗" that is at least my take on this and why I think is very problematic. AI can still be used responsibly as a tool by a white hat hacker under strict supervision to discover zerodays but that is a whole other discussion on how you make sure its not going rouge.
Only if you have a written authorization from the company you try to attack.
Else they are nothing better than a criminal hacker.
I don't feel like many white hat hackers get permission to exploit these vulnerabilities to report them
They get permission when they do it professionally or as a company. Else it is a crime anyway.
It only doesnt seem bad when your gullible to believe what openai writes.
The response isn't terrible, but the fact that it happened in the first place is ridiculous. They don't state anything about fixing the issue on their end so it doesn't happen again. They also don't apologize either or admit that they fucked up, they frame it almost as if they are doing them a favour and should be grateful.