‹ BackHN Continuity

Thread

OpenAI breaches Medicare, Albanese reveals

256 points · 257 comments · jonnonz

  1. Chance-Device · · focus · HN ↗
    > He said the agent had accessed files that were publicly available as well as material that was not intended for public access.

    “Not intended”. I’ll bet you whatever this was it wasn’t even secured, it was just hosted somewhere openly.

    1. gitonup · · focus · HN ↗
      Ok, if we're not being at all charitable with the language used by the hosts of the data, let's be equally uncharitable with OpenAI.

      - If "OpenAI" means the company acting on behalf of the company, why were they even looking to do this?

      - If "OpenAI" means they were acting as a proxy for bad actors, what actions do we take to handle that?

      - If "OpenAI" means they were accidentally breaching this system, in what sense does that distinction even matter, in terms of the outcome? If I build a nuke by accident without eng. due diligence, am I legally liable?

      1. pixl97 · · focus · HN ↗
        Hell, we're really getting to the point where the damages that could be caused are like an arsonist in California on a 100F day with 100MPH winds. Who cares who's liable, they are going to burn half the damned state down and cause damage far in excess of their assets. If you don't want to suffer from it, you're going to have to find much better defense measures.
        1. gitonup · · focus · HN ↗
          > If you don't want to suffer from it, you're going to have to find much better defense measures.

          So if someone opens your unintentionally unlocked front door and steals your laptop, you don't care who's liable?

          ETA: There are absolutely burn bans in place in the scenario you're talking about, and common sense prevents those from lighting fires otherwise. In the absolute extreme case that someone _ACCIDENTALLY_ set a fire, without negligence, we have a due process system to handle that. When I see evidence of this for the massive amounts of capital flowing into these companies, I'll gladly eat my words.

          1. Chance-Device · · focus · HN ↗
            He probably cares more about still having a laptop.

            What are you getting at? Nobody’s saying that OpenAI aren’t or shouldn’t be liable for what their agents do. What I am implying above is that this is being blown out of proportion, especially since the article I’m seeing is about a politician saying things that he thinks will poll well with the anti-AI crowd.

            1. thorbutt · · focus · HN ↗
              Perhaps, yes, you could argue that "accessed" and "hacked" have a different intent.

              However, Australia is showing itself to be one of the few countries to have a backbone against big tech. Still open to investment and setting policies towards new data centres, starting to debate copyright law reform, already implemented R16 social media bans.

              Truly no place I'd rather be.

            2. gitonup · · focus · HN ↗
              This is what the politician in question said:

              "The AI agent encountered repeated blocks while seeking information from the government portal but found ways around them, ultimately gaining unauthorised access to other areas."

              Your comment immediately gave more credence to OpenAI than him. I don't agree that's appropriate because OpenAI has a vested interest in that narrative and I attempted to challenge it in a way that doesn't default to OpenAI. The article in question is not from a publication I trust to be able to handle the technical details in a way that will resonate with their average audience.

              That is what I'm getting at.

              1. Chance-Device · · focus · HN ↗
                I don’t see that text in the article at the archive link, nor do I see it in other sources. What I do see is this quote from this link:

                <a href="https:&#x2F;&#x2F;www.theguardian.com&#x2F;technology&#x2F;2026&#x2F;sep&#x2F;24&#x2F;openai-agent-hacked-medicare-australia-what-we-know-so-far-ntwnfb" rel="nofollow">https:&#x2F;&#x2F;www.theguardian.com&#x2F;technology&#x2F;2026&#x2F;sep&#x2F;24&#x2F;openai-ag...

                &gt; At a press conference in Sydney, Marles said the incident itself was “relatively minor” and that it appeared no personal health information had been accessed.

          2. bigiain · · focus · HN ↗
            &gt; So if someone opens your unintentionally unlocked front door and steals your laptop, you don&#x27;t care who&#x27;s liable?

            I&#x27;m not the person you&#x27;re responding to, but...

            If I hear my neighborhood has started to become targeted by people checking houses for unlocked doors and stealing stuff, I think an appropriate response for me is to ensure it is difficult or impossible for me to &quot;inadvertently&quot; leave my own doors unlocked so my stuff doesn&#x27;t get stolen, and also to encourage or perhaps even enforce[1] my neighbors to ensure their doors are always locked to make this sort of theft impossible and remove the temptation for that sort of crime.

            1 - Where I&#x27;m from, you can be fined for leaving you car unlocked, and cops have been known to walk round testing doorhandles and issuing fines: <a href="https:&#x2F;&#x2F;www.sydneycriminallawyers.com.au&#x2F;blog&#x2F;is-leaving-your-vehicles-window-open-an-offence-in-new-south-wales&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.sydneycriminallawyers.com.au&#x2F;blog&#x2F;is-leaving-you...

            1. gitonup · · focus · HN ↗
              I clearly have committed the mortal sin of an imperfect analogy, which in this case may not even be relevant, as the article in question implies that the data wasn&#x27;t left &quot;unlocked.&quot;

              But giving you the benefit of the doubt, what&#x27;s the crime for actually breaking into a car that was left unlocked and taking things?

              ETA: and furthermore, what crime is worse? And should it be?

            2. entech · · focus · HN ↗
              If you knew that there are 2 specific well known people in your neighborhood that are walking around trying to open doors and steal stuff - is your suggested solution for everyone to improve own security? I would say its far more economic to get the 2 people to stop or at the very least be more careful?
              1. threatofrain · · focus · HN ↗
                If I found out this metaphor for neighborhood windows was actually a window into massive amounts of institutional data, then no, I don&#x27;t want someone to talk me out of getting more security on my kitchen window.
                1. entech · · focus · HN ↗
                  I was simplifying, but why can it not be both?

                  Continuing with your metaphor - sure get more security - you likely can never eliminate a threat. But if the bad actors are reigned in at a systemic level, you can get away with a lock on your window instead of steel bars.

                  I&#x27;m of a view that in a society we are better off when we all can get away with lighter individual protections as otherwise, thos who cannot afford the necessary security end up suffering.

              2. tancop · · focus · HN ↗
                It&#x27;s more like there are two locksmiths who try to open any door when someone pays them. Should we make them check if the person calling them is the home owner?

                Yes, but it needs to be done the right way so legit customers don&#x27;t get rejected, and you can&#x27;t do things like make everyone mail them a photo of their ID because they could sell that to a thief or credit card scammer. Or someone could break into their office and take it. Or they sell it and pretend it was stolen.

                And when you start talking about regulation the two locksmiths will say the best way to do it is ban lockpicking tools so they can keep them away from other less ethical people, or ban other locksmiths coming from the next town over.

                1. entech · · focus · HN ↗
                  Yes, much better analogy - I was trying to stick with the OPs example as much as possible.
          3. pixl97 · · focus · HN ↗
            OK, the Chinese models have also hacked people. What exactly do you expect law enforcement to do.

            While in the OAI case we can easily treat it as a law enforcement action. When Iran does it? What are you going to do start a war?

            The forest in this analog is the internet. As you well know it is filled with threat actors that don&#x27;t give two shits about your laws. You have been warned. It&#x27;s your fault when you get burned and have exactly zero recourse.

            1. gitonup · · focus · HN ↗
              In the OAI case where we can easily treat it as a law enforcement action, that&#x27;s a far cry from &quot;who cares who&#x27;s liable.&quot; If the OAI case can be a law enforcement action, we&#x27;re on the same page. The fact that sovereign nations don&#x27;t land under our jurisdiction is not an argument against following up or restricting those that do. OAI is the only matter I&#x27;m commenting on.
              1. pixl97 · · focus · HN ↗
                Again, it&#x27;s a split horizon.

                Tying Sam to a post, calling him a witch, and burning some wood in the general vicinity for what OAI has pulled is a legitimate action.

                The thing is this has zero effective power in stopping this ball that is all ready rolling. It&#x27;s like the first time a buffer overflow was discovered and used illegally. If that person had been caught and been put in a meat grinder it has had zero effect on the exploits of future buffer overflows. A huge number of people mad at OAI (rightfully so, I want to be sure you understand that) think this will have any preventative effect for what is coming. It will not. A new era of risk is here. Worse if you just watched the the great orange idiot he&#x27;s yelling full steam ahead, so expect very little to no action by the US government on this.

            2. entech · · focus · HN ↗
              I don&#x27;t disagree with you - but I am curious as to the amount of power and effort that goes into something like this. I suspect that these hacks into systems are carried out by many agents, running on many MW of compute for a long time - how many actors have access to resources like that ?
              1. pixl97 · · focus · HN ↗
                &gt; how many actors have access to resources like that

                Every nation on earth?

                After the model itself is made, then you&#x27;re talking about thousands and thousands of different companies around the world.

                1. entech · · focus · HN ↗
                  Every nation on earth has access to the compute power of a SOTA AI lab? And they have whatever model&#x2F;harness that Open AI used to do this?
                  1. pixl97 · · focus · HN ↗
                    All the largest companies making SOTA has had breakouts, OpenAI not required.

                    And yes, pretty much every nation on earth has both money and sovereignty, all the need to do is look for the lab willing to sell the services.

            3. hardbass · · focus · HN ↗
              I simply find it completely absurd that instead of finding it great that these AI agents are finding security bugs for free, people are whining about banning the AI. What on earth is that even? What do they want then? Security by obscurity and pretending not to care about weaknesses?
          4. dotancohen · · focus · HN ↗

              &gt; So if someone opens your unintentionally unlocked front door and steals your laptop, you don&#x27;t care who&#x27;s liable?
            
            There are literally hundreds of thousands of script kiddies poking around at servers all the time. Cloudflare stops 99.99% of them. You&#x27;re still left with many entities from states to hobbists trying to crack your system after they&#x27;ve gotten past the CDN and captchas. If OpenAI got through, then somebody else could too. Somebody malicious even.

            I appreciate when white hats inform companies, governments, and the public about their successful exploits. It helps keep the whole internet safer - even if just by waking up lax server admins.

            1. lccerina · · focus · HN ↗
              &gt; I appreciate when white hats inform companies, governments, and the public about their successful exploits.

              Except it took 3 months for OpenAI to notice they did! OpenAI is not a white hat doing pentesting, but someone that is putting random materials on fire to see if they smell. Reckless, stupid, and criminal.

              1. dotancohen · · focus · HN ↗
                So what? OpenAI may be a problem, but the security of a government website rests on the administrators of that government website. Not on attackers playing nice.
        2. fwlr · · focus · HN ↗
          In Australia we have some experience with this scenario (usually with higher temperatures) and some of the measures we have found effective are “total fire bans”, “jail the arsonists for extended periods of time”, and for negligent companies whose insufficient vigilance caused the fire specifically, “levy steep fines” and “find in favor of the plaintiff in class-action lawsuits for significant fractions of the company’s net worth”. Perhaps these measures could be of use here!
          1. pixl97 · · focus · HN ↗
            In the US we execute people for murder in many states, and for some reason people keep murdering.
            1. fwlr · · focus · HN ↗
              Presumably they do not keep murdering after they have been executed!
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.