Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That’s not how responsible disclosure works.


Yes, I know. Calling it "responsible disclosure" is weaselly and implies that anything else is irresponsible. I disagree.


The term is especially galling when it's applied to undermining a business model. This isn't at all like dropping a 0day on OpenSSH - individuals have zero responsibility for helping businesses maintain artificial restrictions.


I think I agree with you but I want to point out to any young up-and-comers reading this that you shouldn't just naively act like the world agrees, at least not in situations where you have a lot to lose and not much to fall back on. It's like piracy. Yes, intellectual property law is stupid and should be thwarted whenever possible, and we can talk like that all we want. Just be careful with your actions.


General topic is independent disclosure. If something is more responsible or irresponsible is dependent on the context. In this specific situation I not seeing any reason why publicly disclosing this prior to notifying OpenAI would have been more responsible. Am I missing something?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: