fwiw, i’m going to stop talking about the openai thing. we made our points pretty clearly, one final note.
to hackers:
1. most serious companies will receive good-faith research like this gracefully and treat you well. they don’t question your intent or threaten you, they look at your profile, your history, and the work itself, and that usually estables bridge quiet quickly.
2. yes, some of the "old and outdated people who are not following the state of vdp," as someone put it, are right about the risky waters.
don’t randomly test every company, stick to top companies. nd yes, they are right about pivoting too, opening pr is one thing, cloning openai’s source code or exfiling ci secrets and starting to hunt for model weights would obviously be a crazy step too far.
3. have your own disclosure policy, i will attach down below ours, 30/90 days, whatever you believe is reasonable. personally, i wouldn’t sell my sole or sell away control of my research for money, being able to show your work publicly goes very far.
you can call that chasing fame. i call it keeping my agency over my own work and proudly showing people what we built.
4. when you choose to publish, understand that publication is opposite of what a ciso wants, occasionally people will become antagonistic.
try to talk sense into them, a vdp does not have to become an embarrassing story, it can become a great one.
case in point, google cloud had nasty bugs disclosed publicly all the time, researchers wrote detailed posts about them, and google celebrates security research every year, highlights top bugs, and has people like
@LiveOverflow make videos about them.
Hacking into Google's Network for $133,337:
piped.video/watch?v=g-JgA1hv…
StubZero: $148,337 RCE in Google Cloud Production
brutecat.com/articles/google…
---
to security leaders:
1. please, you don’t need to be asinine.
2. researchers are doing something useful for society and for your company, even when they also have their own interests
3. treat them well, learn from google or meta, vulnerability research works best as a collaboration, not a threatening relationship