OpenAI bug disclosure sparks CFAA debate as researcher defends good-faith repo access test
ns123abc · x · 2026-09-21
A security researcher details how their team responsibly disclosed a Codex on cloud repo-access bug—proving access with a harmless PR and deliberately avoiding sensitive data—only to face an angry CISO who invoked potential CFAA violations and authorization-boundary disputes.
The researcher argues CISOs are right to investigate but wrong to treat good-faith, minimally-invasive researchers as adversaries. Alex Stamos pushes back, citing the Sullivan case and misprision of felony to explain why OpenAI demanded detailed logs, claiming bug bounty participants have been spoiled by lax CFAA enforcement. The exchange exposes a rule vacuum between AI companies' security teams and the traditional bug bounty ecosystem.
More from Safety
- China's top AI labs raised ~$35B in five months; combined haul could hit $60B by 2027 — FinanceYF5 · 2026-09-21
- Ezra Klein buys into AI X-risk worldview, and skeptics admit they're losing the argument — zetalyrae · 2026-09-21
- Today's models already outsmart humans, so why talk of guarding against superintelligence? — ctjlewis · 2026-09-21
- GuardianAgent: EMNLP Paper Teaches AI Agents to Fight Back Against Web Tracking — flosalim · 2026-09-21
- EU LLM apps: developer maps the 5 blockers between prototype and paid launch — felix_baron · 2026-09-21
- Nordic institute report: EU AI sovereignty means being indispensable, not self-sufficient — nordicinst · 2026-09-21