Ex-Apple Engineer Uses Dumb Authentication Bug to Steal Secrets for OpenAI
When your security is so legendary that an ex-employee can just log back in from his new desk at OpenAI to copy-paste upcoming hardware specs. Truly, the pinnacle of trillion-dollar engineering.
An electronics engineer named Chan Liu packed his bags at Apple, walked right into the offices of OpenAI, and apparently forgot that he was no longer on the payroll. Instead of the usual awkward goodbye emails, he allegedly spent his first few weeks at his new job browsing his former employer's internal servers to download a treasure trove of confidential hardware files.
The tech giant's security team apparently left the backdoor wide open. According to a lawsuit filed in California, Chan Liu stumbled upon a rare, previously unknown zero-day authentication bug that allowed him to bypass network security. Instead of doing the ethical thing and reporting the flaw, he treated it as a VIP pass to look at unreleased product details, engineering presentations, and secret technical specifications.
To make matters even more cartoonish, the engineer did not even bother to return his company-issued laptop. When Apple asked for it back, he simply claimed he had another computer, while secretly using the corporate machine to ping internal servers. He also allegedly borrowed another Apple laptop belonging to his friend Yu-Ting Peng, who was still working there at the time but was also planning her escape to OpenAI.
The heist was uncovered when investigators found server logs of him accessing the repository. In a moment of pure corporate comedy, Chan Liu even texted Yu-Ting Peng to brag about his digital break-in, literally writing: "Lol, I found out I can access [network storage], so funny."
It turns out that the most sophisticated AI lab in the world and the most valuable hardware company on earth are ultimately at the mercy of basic password security and employees texting "lol" while raiding the cookie jar. If a trillion-dollar company cannot even revoke a laptop's access after firing someone, the grand promises of ironclad corporate security and unhackable systems look like nothing more than a very expensive joke.
Source: TechCrunch
Comments
This is where the magic happens: AI reads your discussion and rewrites the article based on the most interesting comments. Each strong comment adds points to the meter below. Once the meter is full, the article updates live — no page reload needed.