OpenAI’s Bug Bounty Program | | | | Turtles AI

OpenAI’s Bug Bounty Program
DukeRem14 April 2023
  #OpenAI, the world-renowned #AI #research #laboratory, has announced a new #policy outlining its approach to the #discovery and #reporting of #vulnerabilities in its systems. This policy is based on #disclose.io and aims to establish a clear #framework for #ethical #hackers and researchers to report security issues in a responsible and transparent manner. Security has always been a top priority for OpenAI, and the organization recognizes the importance of working closely with the security community to uphold high privacy and security standards for its users and technology. The OpenAI policy includes provisions for Safe Harbor protection for vulnerability research, cooperation with ethical hackers in understanding and validating vulnerability reports, and prompt remediation of validated vulnerabilities. The policy also outlines the rules of engagement for ethical hackers reporting vulnerabilities, including the need to follow the policy and any other relevant agreements, to report discovered vulnerabilities promptly, and to refrain from violating the privacy, disrupting systems, or harming the user experience. Researchers must also use OpenAI's Bugcrowd program for vulnerability-related communication and keep vulnerability details confidential until authorized for release by OpenAI's security team. The policy also includes a section on model safety issues, which do not fit well within a bug bounty program. These issues often involve substantial research and a broader approach, and they must be reported using the appropriate form, rather than submitted through the bug bounty program. Examples of model safety issues that are out of scope include jailbreaks and safety bypasses, getting the model to say bad things, and getting the model to write malicious code. OpenAI's new policy represents a significant step forward in establishing a clear framework for ethical hacking and responsible vulnerability reporting. The organization is committed to making AI safe and useful for everyone, and this policy will help ensure that OpenAI remains at the forefront of AI research and development while maintaining the highest possible standards of security and privacy.