Live data from Hacker News

OpenAI – vulnerability responsible disclosure

requilence.any.org

51–60 of 87 posts

Re: OpenAI – vulnerability responsible disclosure

#51

Earlier quoted context omitted.

i had the exact same behavior back in 2023, it seemed like clearly leakage of user conversations - but it was just a bug with api calls in the software i was using. https://snipboard.io/FXOkdK.jpg

There was an issue with conversation leakage, though. It involved some bug with Redis. I felt like it was a huge deal at the time but it’s surprisingly hard to quickly google it.

It was the classic "oh no we did caching wrong" bug that many startups bump into. It didn't expose actual conversations though, only their titles: https://openai.com/index/march-20-chatgpt-outage/

Re: OpenAI – vulnerability responsible disclosure

#53
post #20

Earlier quoted context omitted.

It's not just about sensitive data like passwords, contracts, or IP. It's also about the personal conversations people have with ChatGPT. Some are depressed, some are dealing with bullying, others are trying to figure out how to come out to their parents. For them, this isn't just sensitive, it's life-changing if it gets leaked. It's like Meta leaking their WhatsApp messages. I really hope they fix this bug and start…

maybe you should stop trusting random people on the internet making extraordinary claims without proof then?

https://arstechnica.com/tech-policy/2025/07/nyt-to-start-sea...

Re: OpenAI – vulnerability responsible disclosure

#54
post #34

> I am issuing this limited, non‑technical disclosure: > No exploit code, proof‑of‑concept, or reproduction steps are included here. Then why bother? I feel a bit cynical here, but if the goal is to get this fixed, they're not going to care unless it becomes a zero day and is given to the masses, otherwise it's going to quietly be exploitable by the few unsavory groups who know of it and will never be patched. Isn't…

It adds some pressure, we know now what the bug is about so we can guess which endpoints to poke at, then it's only a matter of time before it leaks. It would be unethical for the researcher to just publish it.

Re: OpenAI – vulnerability responsible disclosure

#56

Reported a flaw to OpenAI that lets users peek at others' chat responses. Got an auto-reply on May 29th, radio silence since. Issue remains unpatched :( Avoided their bug bounty due to permanent NDAs preventing disclosure even after fixes. Following standard 45-day disclosure window—users should avoid sharing sensitive data until this is resolved.

I see other users conversations on my Gemini dashboard, not sure who to even complain to.

Software quality is... Minimal now days.

Re: OpenAI – vulnerability responsible disclosure

#57
post #43

Earlier quoted context omitted.

Coming up with accurate financial data that you can't get it to report outright doesn't seem like one.

I don't understand the wording Accurate financial data? How do we know? What does using not-web-search not having the data have to do with the claim that private chats with the data are being leaked?

> I found this company; it is real and numbers in the response are real.

???

Re: OpenAI – vulnerability responsible disclosure

#58

Earlier quoted context omitted.

maybe you should stop trusting random people on the internet making extraordinary claims without proof then?

https://arstechnica.com/tech-policy/2025/07/nyt-to-start-sea...

This is going to be subject to the legal discovery process with the usual safeguards to prevent leaks; in particular, the judge will directly supervise the decision of who needs access to these logs, and if someone discloses information derived from them for an improper purpose, there's a very good chance they'll go to jail for contempt of court, which is much more stringent than you can usually expect for data privacy. You can still quite reasonably be against it, but you cannot reasonably call it "plain text logs available for everyone at the company to view".

Re: OpenAI – vulnerability responsible disclosure

#59
post #51

Earlier quoted context omitted.

There was an issue with conversation leakage, though. It involved some bug with Redis. I felt like it was a huge deal at the time but it’s surprisingly hard to quickly google it.

It was the classic "oh no we did caching wrong" bug that many startups bump into. It didn't expose actual conversations though, only their titles: https://openai.com/index/march-20-chatgpt-outage/

ah there it is. thanks for jogging my memory. funny to think of how niche chatgpt was considered then to now.

Re: OpenAI – vulnerability responsible disclosure

#60
post #22

> The leaked responses show clear signs of being real conversations: they start with contextually appropriate replies, sometimes reference the original user question, appear in various languages, and maintain coherent conversational flow. This pattern is inconsistent with random model hallucinations but matches exactly what you'd expect from misdirected user sessions. A model like GPT-4o can hallucinated responses th…

In one of the responses, it provided the financial analysis of a not well-known company with a non-Latin name located in a small country. I found this company; it is real and numbers in the response are real. When I asked my ChatGPT to provide a financial report for this company without using web tools, it responded: `Unfortunately, I don’t have specific financial statements for “xxx” for 2021 and 2022 in my training…

I’m struggling to understand why you are so adamant that this is proof.
Post reply on HN