OpenAI bug disclosure sparks CFAA debate as researcher defends good-faith repo access test

ns123abc · x · 2026-09-21

A security researcher details how their team responsibly disclosed a Codex on cloud repo-access bug—proving access with a harmless PR and deliberately avoiding sensitive data—only to face an angry CISO who invoked potential CFAA violations and authorization-boundary disputes.

The researcher argues CISOs are right to investigate but wrong to treat good-faith, minimally-invasive researchers as adversaries. Alex Stamos pushes back, citing the Sullivan case and misprision of felony to explain why OpenAI demanded detailed logs, claiming bug bounty participants have been spoiled by lax CFAA enforcement. The exchange exposes a rule vacuum between AI companies' security teams and the traditional bug bounty ecosystem.

Related event: OpenAI Bug Disclosure Backlash: Security Community Slams CISO Before Reconciliation(14 posts)→

Original post →

More from Safety

Safety channel →