Live data from Hacker News

GPT‑5.5 Bio Bug Bounty

openai.com

111–114 of 114 posts

Re: GPT‑5.5 Bio Bug Bounty

#111
25.000 for something you could either sell it for much more or put it free to cause them much more than 25k in damages for sure. Why this bounty is so low? They can't even argue that the prompt itself is a hack because that's just text. I'd they do, they need to rethink everything on how they fetch data for their models.

Re: GPT‑5.5 Bio Bug Bounty

#112
This is very much within my areas of interest, but signing an NDA in this area is a lot to ask. I'm hoping someone that gets shown the NDA, but doesn't sign it, would be willing to post more details. Such as: does the NDA just cover the questions given or the entire experience of interfacing with the api? And how long does it last?

Re: GPT‑5.5 Bio Bug Bounty

#113

I could probably do this, but why on earth would I want to immediately put myself on a list as a dangerous person. The main problem with this is, even if somehow they stopped all points of failure with gpt5.5 which they can't, you can distill a new model from gpt5.5 or any other model and get anything you would want in probably under 4b parameters. A lot of this is theater so they don't get sued as easily when it ine…

How can you distill a model from a closed-weights model like this? I've never heard of model reverse engineering.

https://www.rand.org/content/dam/rand/pubs/research_reports/...

Re: GPT‑5.5 Bio Bug Bounty

#114

Earlier quoted context omitted.

1-hope folks don’t resort to that 2-@C-suite, look what y’all wrought saving a penny, pls fix (btw #1 is my polite way of saying “don’t do it!” - plea as I might, if the thinking gains traction people will sell more 0days anyway, so might as well fix bounty programs now before it’s in the news)

I'm not advocating for any behavior in particular. It could be anything from telling the company, to saying nothing, to doing something evil with it. It's each individual's choice. I just wanted to reiterate it so the folks in the back of the room hear that it is a matter of routine for companies to deny paying out legitimate bug bounties at this point and that should be known to the bug finders when deciding what to…

Let’s hope the good guys stay the good guys by paying ethical hackers what they’re worth!
Post reply on HN