Hacker Newsnew | past | comments | ask | show | jobs | submit | da_grift_shift's commentslogin

Is there back-and-forth? How long do these get? Can you share an example?

>you might have some false memories or incorrect instructions in your CLAUDE.md

    "YOU'RE HOLDING IT WRONG!"

did you internalize what was wrong with that quote when it was said? does it apply here?

>We appreciate the security research here

>it’s unfortunate this one slipped through a crack in our disclosure pipeline

>As we’re now aware of this report

This isn't the first time. https://x.com/PhilipTsukerman/status/1988634162773778501 https://x.com/_xpn_/status/1986382527817564437

What very likely happened here is you received good faith security research by email and you forced the researcher to submit through HackerOne or Bugcrowd or whatever, which mandates their compliance with Platform Terms and Disclosure Terms and Codes of Conduct and whatnot.

The SECURITY.md files in your GitHub repos only mention the email address. Can researchers like this one report issues via email and get a response, or not?

    May 08, 2026    PromptArmor discloses to OpenAI via email
    May 08, 2026    OpenAI sends an automated reply, confirming the intended reporting channel
    May 08, 2026    PromptArmor confirms email preference
    May 12, 2026    PromptArmor follows up
    May 18, 2026    PromptArmor follows up


What's with the fox performing phrenology on a sheep in the generated image captioned "The moment we realized it was us"?


>"Google investing $40B in Anthropic while also competing against them is the most Silicon Valley thing I've ever seen. These companies will fund their own competition just to make sure they have a seat at the table when it wins. Also $800B valuation for a company that hasn't IPO'd yet?? We are so cooked."

Who are you quoting?


The [THING] has been living rent-free in my head since [YEAR]. Also the fact that [THING]. No [X]. No [Y]. No [Z]. Just: [A]. Absolute [HYPERBOLE] energy.

At least this comment didn't have the double quotes left in ˙ ͜ʟ˙


Stylometry avoidance is not a valid excuse for factual omissions, fabrications, and "DYOR dumping" (bullshit asymmetry).


Wow. The advisories page is worthy of a post in itself.



Sure, but the source blogpost isn't.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: