Live data from Hacker News

200k Compromised OpenAI Credentials Available for Purchase on the Dark Web

cpomagazine.com

31–40 of 77 posts

Re: 200k Compromised OpenAI Credentials Available for Purchase on the Dark Web

#31
post #6

I'm curious about the logistics here, what's preventing OAI from obtaining a copy and invalidating those credentials?

wouldn't that reward the seller, and still be potentially costly for OpenAI?

Any security researcher wanting to analyze the data (or Troy Hunt wanting to add it to haveibeenpwnd.com) will imply someone rewarding the seller, that's inevitable. The sooner, the less the seller can make on this data.

Re: 200k Compromised OpenAI Credentials Available for Purchase on the Dark Web

#32

> The stolen OpenAI credentials were stolen using Raccoon Infostealer (78,348), Vidar (12,984), and RedLine (6,773) malware variants. Nothing to worry about unless you had malware on your computer -- sniffing all your data, OpenAI credentials included. It is only news because ChatGPT logs potentially have exploitable data in them. Another misleading headline -- OpenAI has not been compromised.

It's kind of vague about how these malware work. Are they keylogging (recording keystrokes as you type the password)?

Re: 200k Compromised OpenAI Credentials Available for Purchase on the Dark Web

#33
post #10

I seriously wonder why, given the Microsoft deal, OpenAI didn't just cede all product development and production-izing of their models to MS while they focus on research. I know smart people work there, some friends included, but OpenAI was never a product-led startup, they were a research org. Ignoring the closed vs open debate for a moment: for all the talk of focus, focus, focus from YC, it seems unfocused to ship…

What did OpenAI do wrong here? As far as I can tell they're guilty of requiring logins?

It's not requiring logins per se -- this is the second mishap I'm aware of related to their consumer product surface area (the first being users' chat data going to other users). Just seems like a distraction, if the goal is to do fundamental AI research.

Re: 200k Compromised OpenAI Credentials Available for Purchase on the Dark Web

#34
post #10

I seriously wonder why, given the Microsoft deal, OpenAI didn't just cede all product development and production-izing of their models to MS while they focus on research. I know smart people work there, some friends included, but OpenAI was never a product-led startup, they were a research org. Ignoring the closed vs open debate for a moment: for all the talk of focus, focus, focus from YC, it seems unfocused to ship…

Noob Thought on why OpenAI collaborated with MS:

1. I have found ChatGPT is very good at parroting back decent quality from learning from structured data. For example, learning reasonable code completions as well as answering technical questions. I find ChatGPT very good resource to have inside VSCode instead of switching to google. 6-7/10 I will accept GPTs output in Copilot.

2. My guess is that Microsoft's pretty chunk of profit is from selling Developer software(or so it is trying to do).

Put 1 + 2 together and you have a pretty compelling product play.

Re: 200k Compromised OpenAI Credentials Available for Purchase on the Dark Web

#35
post #10

I seriously wonder why, given the Microsoft deal, OpenAI didn't just cede all product development and production-izing of their models to MS while they focus on research. I know smart people work there, some friends included, but OpenAI was never a product-led startup, they were a research org. Ignoring the closed vs open debate for a moment: for all the talk of focus, focus, focus from YC, it seems unfocused to ship…

What did OpenAI do wrong here? As far as I can tell they're guilty of requiring logins?

He didn't read the article. Headline and comment.

Re: 200k Compromised OpenAI Credentials Available for Purchase on the Dark Web

#36
post #10

I seriously wonder why, given the Microsoft deal, OpenAI didn't just cede all product development and production-izing of their models to MS while they focus on research. I know smart people work there, some friends included, but OpenAI was never a product-led startup, they were a research org. Ignoring the closed vs open debate for a moment: for all the talk of focus, focus, focus from YC, it seems unfocused to ship…

you didn't read the article.

The stolen OpenAI credentials were stolen using Raccoon Infostealer (78,348), Vidar (12,984), and RedLine (6,773) malware variants.

Just my 2 cents.

Re: 200k Compromised OpenAI Credentials Available for Purchase on the Dark Web

#37
Is there anything interesting about this story besides that it has OpenAI in the headline?

I assumed there was a data breach, but no, this is just 200k credentials stolen from people's computers with normal malware. There are billions of credentials available for sale on the dark web. This particular set doesn't seem significant at all besides that anything with OpenAI gets extra clicks these days.

Re: 200k Compromised OpenAI Credentials Available for Purchase on the Dark Web

#38
post #10

I seriously wonder why, given the Microsoft deal, OpenAI didn't just cede all product development and production-izing of their models to MS while they focus on research. I know smart people work there, some friends included, but OpenAI was never a product-led startup, they were a research org. Ignoring the closed vs open debate for a moment: for all the talk of focus, focus, focus from YC, it seems unfocused to ship…

Because when you accidentally discover a golden goose, you don’t give it to Microsoft, you learn to cook eggs. I had the same thought as you at first, and many people speculated they’d shutter ChatGPT in favor of the API being served to others. But while anyone can sell an API, making a consumer product people want is just too rare to give it up. It’s better to learn how to service consumers and satisfy the demand. E…

That's my worry, too. I'm reminded of the history of Intel, which at its founding decided that it would not have a research org (drop the R from R&D) and just focus on scaling FETs, because the founders learned that trying to do both meant that one would ultimately suffer.

Re: 200k Compromised OpenAI Credentials Available for Purchase on the Dark Web

#39
post #33

Earlier quoted context omitted.

What did OpenAI do wrong here? As far as I can tell they're guilty of requiring logins?

It's not requiring logins per se -- this is the second mishap I'm aware of related to their consumer product surface area (the first being users' chat data going to other users). Just seems like a distraction, if the goal is to do fundamental AI research.

I think you're missing the point: this isn't a mishap that has anything to do with OpenAI. If you are a company that has usernames and passwords, then your login information is for sale because your customers have malware on their computers. OpenAI didn't do anything wrong here besides have a ton of users, many of which had malware on their computers.

From the article:

> However, the ChatGPT parent company clarified the compromised login credentials were not the result of any OpenAI data breach. Instead, they were the by-product of commodity malware-based log harvesting.

Re: 200k Compromised OpenAI Credentials Available for Purchase on the Dark Web

#40
post #10

I seriously wonder why, given the Microsoft deal, OpenAI didn't just cede all product development and production-izing of their models to MS while they focus on research. I know smart people work there, some friends included, but OpenAI was never a product-led startup, they were a research org. Ignoring the closed vs open debate for a moment: for all the talk of focus, focus, focus from YC, it seems unfocused to ship…

you didn't read the article. The stolen OpenAI credentials were stolen using Raccoon Infostealer (78,348), Vidar (12,984), and RedLine (6,773) malware variants. Just my 2 cents.

[flagged]
Post reply on HN