Security Row: Was the 0-Day PR in OpenAI's GitHub Repo Responsible Disclosure or a Bridge Too Far?
joshua_saxe · x · 2026-09-21
- Security researcher Tal BeerySec argues that when you find a 0-day in a public service, you do responsible disclosure, not lateral movement — calling the PR submitted in @OpenAI's GitHub repo "a bridge too far."
- joshuasaxe counters: right on rules, wrong on public interest. He says now is exactly the time for dramatic wake-up calls about weights security, algorithmic secrets security, and user data security, and is glad HacktronAI did what they did.
- The exchange highlights a real split in the AI security community over where white-hat boundaries lie when AI giants' core assets are at stake.
More from Safety
- csuwildcat on AI data compensation: creators needn't care about the payout black box — csuwildcat · 2026-09-21
- China posts new crypto standard candidates; 14 attacked by one person next day — StefanoGogioso · 2026-09-21
- NIST's CAISI publishes assessment of Z.ai's GLM-5.3 cyber capabilities — 233C · 2026-09-21
- 16 Critical Breaks Hit NGCC Post-Quantum Candidates; Researcher Launches Own Forum — jedisct1 · 2026-09-21
- AI product privacy: derived data and behavioral data need protection too — goyalshaliniuk · 2026-09-21
- 5 Types of Data Every AI App Should Protect, From PII to Behavioral Signals — goyalshaliniuk · 2026-09-21