upvote
My guess is that OpenAI has done a lot more to prevent exfil of their model weights than the codebase of their main web app and client.
reply
Perhaps the exploit was not as large or dangerous as the team says it is.
reply
It's a monorepo and they're at over 1 million PRs. There's surely some juicy stuff there.
reply
[dead]
reply
The unfortunate truth of doing the right thing. Also, correct me if I'm wrong but there are too many bad things out there and companies can't give 1 million bounty for stuff like that. I'm sure they could but in the long run, wouldn't it be unsustainable?
reply
It’s an interesting bet then.

Pay next to nothing every time, accept one financially-depressed researcher sale to blackhats causing tremendous business disruption every n years. Cheaper than honest payouts to [keep] researchers [honest]? Keep paying chump change. (Booo)

reply
How much would a nation state pay for a complete copy of OpenAI’s github repositories? I doubt there are many full chains laying around like this.
reply
No more unsustainable than these companies already are by default. The bounty should have been proportionate to how important and pressing the findings were.
reply