this post was submitted on 01 Oct 2026
241 points (98.0% liked)
Technology
88390 readers
3242 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Am I mentally fried or does this seem completely fine? The recon was surface level and it seems to have been responsibly disclosed.
There are two major problems here:
On top of that, the time it took for the notice to go through the channels here in Australia was ridiculous.
sounds like failure of all parties. ducks
That was my thought exactly. Agent broke in, read some files (no mention of PII or confidential things) to confirm read access, dropped a test file to confirm write access, sent an email explaining that's bad with a few details.
Being on the defensive side myself, if I received that from a human I'd be grateful.
Edit: from the bad screenshot, the email was even sent to the right email: "PUBLIC DISCLOSURE". So the target does accept such reports.
Best for the company? probably.
Morally clear? grey. If their 'hacking' accidentally causes issues with the system or it goes down, it's definitely bad. Whatever was on that system is now in the hands of OpenAI, not great. Because OpenAI is open about it, a lot of people who are even less reputable will do it.
Historically, Pentesting had unwritten rules of engagement. None of that is being followed.
We don't seem to apply law to AI, that's a real problem.
But still, best for the company/entity, yeah.
Well do we trust OpenAI?