‹ BackHN Continuity

Thread

OpenAI breaches Medicare, Albanese reveals

256 points · 257 comments · jonnonz

  1. binlog · · focus · HN ↗
    Zero technical details on what the "hack" actually was. Willing to bet it was something as stupid as the data being accessible by changing the query parameter, and rather than own up to their own shoddy security (no doubt built by an offshore contractor) they are going to blame the one who found and reported the bug.
    1. MichaelDickens · · focus · HN ↗
      Does it matter whether the data was poorly secured? LLMs should not be hacking into government medical websites, and if they do, the companies responsible should disclose the incidents as soon as possible.
      1. uoaei · · focus · HN ↗
        Yes, it is their responsibility as stewards of their citizens' data. What point are you making with the word "should"?
        1. selcuka · · focus · HN ↗
          Sure, it is their responsibility, but that doesn't answer the question "Does it matter whether the data was poorly secured?"

          If your house is robbed, does it matter whether you didn't have a state-of-the-art lock? A robbery is still a robbery.

          1. noosphr · · focus · HN ↗
            <a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=pbKUv0701vE" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=pbKUv0701vE

            It very much does matter.

          2. shard972 · · focus · HN ↗
            Is it robbery when in this case it was a sign with information that you were planning on putting on your front fence for public display but while preparing it was left sitting in the front yard with a small fence.

            If I walked past, saw it and remembered it or even recorded it, is that honestly theft?

      2. handoflixue · · focus · HN ↗
        The problem is that sufficiently poor security is indistinguishable from authorized public access. And unfortunately a lot of real world &quot;digital security&quot; is in fact that bad.

        A lot of these &quot;hacks&quot; are the equivalent of asking &quot;hey, can I come in?&quot; and the guard assuming that anyone who would ask is authorized, and thus saying &quot;yes&quot;. But if the guard said &quot;yes&quot; then it seems a bit absurd to call it trespassing.

        1. j_maffe · · focus · HN ↗
          I highly doubt given OAI&#x27;s latest streak that the models didn&#x27;t know what they were doing.
        2. noosphr · · focus · HN ↗
          More like:

          &gt;Hey can I come into room 1?

          Sure. That&#x27;s the lobby.

          &gt;How about room 101?

          Sure. That&#x27;s where we keep the nuclear launch button. Don&#x27;t press anything red.

          1. handoflixue · · focus · HN ↗
            Oh but you see, only an evil hacker would ever even think to ask about a room that wasn&#x27;t theirs!
            1. ShinyLeftPad · · focus · HN ↗
              This but without sarcasm?

              Hacker or pentester.

          2. andrewstuart · · focus · HN ↗
            &gt;&gt; Don&#x27;t press anything red.

            Nope. There’s just a sign saying “red = launch nukes”.

            Or maybe just a red button.

            Or maybe just a green button that launches the nukes, without so much as “are you sure?”.

      3. dzhiurgis · · focus · HN ↗
        I agree. Government shouldn&#x27;t be running medical websites.

        Leave it to private enterprises who can actually secure it.

        1. rainonmoon · · focus · HN ↗
          Totally. <a href="https:&#x2F;&#x2F;www.bbc.com&#x2F;news&#x2F;world-australia-68064850" rel="nofollow">https:&#x2F;&#x2F;www.bbc.com&#x2F;news&#x2F;world-australia-68064850
          1. hiharryhere · · focus · HN ↗
            I’m assuming sarcasm here?

            That link describes a hack of Medibank, which is a private company.

            1. rainonmoon · · focus · HN ↗
              Correct.
        2. Sharlin · · focus · HN ↗
          Poe’s law is very strong here.
        3. deterministic · · focus · HN ↗
          Yep, because private enterprises never go bankrupt, commit fraud, mistreat customers, bribe politicians, put profit ahead of safety, hack websites, etc. etc.

          What world are you living in?

      4. vorticalbox · · focus · HN ↗
        lets say you have page=0 some of these pages are public and some are private, and the only way you secure the private pages is to not link it on the website.

        is incrementing a url query parameters from 0 -&gt; 1 count as hacking?

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.