Reported a flaw to OpenAI that lets users peek at others' chat responses. Got an auto-reply on May 29th, radio silence since. Issue remains unpatched :(
Avoided their bug bounty due to permanent NDAs preventing disclosure even after fixes. Following standard 45-day disclosure window—users should avoid sharing sensitive data until this is resolved.
jonrouach|7 months ago
https://jarbon.medium.com/gpt-prompt-bug-94322a96c574
requilence|7 months ago
999900000999|7 months ago
A lot of AI products straight up have plan text logs available for everyone at the company to view.
pyman|7 months ago
I really hope they fix this bug and start taking security more seriously. Trust is everything.
ameliaquining|7 months ago
poniko|7 months ago
tptacek|7 months ago
com2kid|7 months ago
Software quality is... Minimal now days.
fcpguru|7 months ago
requilence|7 months ago
maxlin|7 months ago
tptacek|7 months ago
unknown|7 months ago
[deleted]