HNHacker News
TopNewBestAskShowJobs

rot09

25 karma · joined September 22, 2026

software security engineer
submissionscomments
rot09··on OpenAI still doesn't seem to have a handle on all of its rogue AI activity
This lines up. In the infosec community it is well known that OpenAI did not hire many security engineers or researchers pre-April 2026.

There has been a crazy hiring push from both companies to poach security engineers/researchers from Google, Apple, and Meta since Q2/Q3, but the response was very delayed. Many talented security engineers/researchers I know at Apple/Google/Meta (including myself) receiving these offers are worried about taking them due to the risks of criminal/personal liability and the more likely risk of tarnishing their careers.

rot09··on OpenAI agents tried to bruteforce a UN website's API fields
I need to make a correction in my post above. Anthropic's actions are inline with Google and Meta. OpenAI is the only frontier lab that has showcased gross negligence.
rot09··on OpenAI agents tried to bruteforce a UN website's API fields
If I train a model at my house on my workstation, execute it, and under my supervision it ransomwares a hospital and somebody dies. What would be a just punishment for me?

Now the reality, the openai engineers trained a model, executed it, and under their supervision (no users were involved) it committed so many felonies that we are learning about a new one every week. What would be a just punishment for OpenAI?

rot09··on OpenAI agents tried to bruteforce a UN website's API fields
It's very likely they just haven't detected or disclosed the Aug-Sept 2026 hacks yet.
rot09··on OpenAI agents tried to bruteforce a UN website's API fields
OpenAI's sandbox misconfigurations were egregious. The other frontier labs (Meta and Google) have many more security engineers and researchers on staff, and that's likely why you haven't read as many damning headlines about them. OpenAI and Anthropic talk a lot about cybersecurity safety, but instead of using it as an opportunity to increase their security engineering/researcher headcount they are just reassigning SWEs and PEs to do security engineering work.

It's pretty obvious now to everyone that OAI and Ant do not take cybersecurity seriously. It will not be a priority unless they are held accountable. This is sadly how it always goes, but usually it's the company getting breached/ransomed/fined that triggers them to actually start taking security seriously, not company insiders committing felonies with the tools they built :)

rot09··on Revealing the details of how OpenAI agents hacked Hugging Face
Agreed. In the infosec community it is well known that OpenAI and Anthropic did not hire many security engineers or researchers pre-April 2026. It seems pretty negligent.

There has been a crazy hiring push from both companies to poach security engineers/researchers from Google, Apple, and Meta since Q2/Q3, but the response was incredibly delayed. Many talented security engineers/researchers I know at Apple/Google/Meta (including myself) receiving these offers are worried about taking them due to the risks of criminal/personal liability and the more likely risk of tarnishing their careers.

rot09··on OpenAI agent hacked Australian government website, PM says
Not a lawyer and this is not legal advice, but I did ask my lawyer about the potential personal risks after receiving an offer. I used that as a data point when I declined the offer and for my speculative comment.
rot09··on OpenAI agent hacked Australian government website, PM says
In the infosec community it is well known that OpenAI and Anthropic did not hire many security engineers or researchers pre-April 2026. There is likely a case for gross negligence (IANAL).

There has been a crazy hiring push from both companies to poach security engineers/researchers from Google, Apple, and Meta since Q2/Q3, but the response was incredibly delayed. Many talented security engineers/researchers I know at Apple/Google/Meta (including myself) receiving these offers are worried about taking them due to the risks of criminal/personal liability and the more likely risk of tarnishing their careers.