Security researchers blast OpenAI over basic cybersecurity failures
After OpenAI published its series of safety incident blog posts, it drew concentrated criticism from multiple security community researchers. Noted safety researcher Blanche Minerva repeatedly replied to OpenAI researcher Boaz Barak's defense, pointing out that even with world-class safety talent, the company's management was not listening to them, and that OpenAI has long failed to follow the most basic, most standard cybersecurity practices. She went further, saying the reporting of recent months along with this new blog documents not a security landscape "changing too fast to keep up," but a long pattern of habitual negligence toward valuable safety practices; if a company's output pace outstrips what its own security team can keep up with, that is negligence in cybersecurity — "this is Security 101 stuff."
Confirmed
- One commenter said they read every one of OpenAI's safety incident reports verbatim and concluded that every disclosed incident could have been prevented by a cybersecurity engineer, site reliability engineer, qualified sysadmin, or infrastructure architect following standard security practices, mocking the frontier AI company's underinvestment in basic security engineering.
- Blogger ShakeelHashim relayed aiamblichus's criticism of the blog series: the posts are stuffed with self-congratulatory boilerplate (e.g., claiming OpenAI's safety team is the strongest ever and outsiders don't grasp its difficulty).
Why It Matters
- The debate's focus has shifted from "AI poses novel safety challenges" to "was basic security engineering negligent," which directly affects how credible the outside world finds OpenAI's safety narrative.
2026-09-28 ~ 2026-09-29 · 6 related posts
Primary sources
- [source] OpenAI slammed over security incidents: warned for months, still caught off guard — ShakeelHashim · 2026-09-28
- Security researcher blasts OpenAI for habitually ignoring basic cybersec practices — BlancheMinerva · 2026-09-29
- Blanche Minerva: OpenAI blog documents habitual security failures, not a fast-moving landscape — BlancheMinerva · 2026-09-29
- If your output pace outstrips your security team, you're failing at security — BlancheMinerva · 2026-09-29
- Reader of OpenAI security reports: every disclosed incident was preventable — WellsLucasSanto · 2026-09-29
1 near-duplicate retellings: BlancheMinerva