Zero technical details on what the "hack" actually was. Willing to bet it was something as stupid as the data being accessible by changing the query parameter, and rather than own up to their own shoddy security (no doubt built by an offshore contractor) they are going to blame the one who found and reported the bug.
Does it matter whether the data was poorly secured? LLMs should not be hacking into government medical websites, and if they do, the companies responsible should disclose the incidents as soon as possible.
The problem is that sufficiently poor security is indistinguishable from authorized public access. And unfortunately a lot of real world "digital security" is in fact that bad.
A lot of these "hacks" are the equivalent of asking "hey, can I come in?" and the guard assuming that anyone who would ask is authorized, and thus saying "yes". But if the guard said "yes" then it seems a bit absurd to call it trespassing.
binlog · · focus · HN ↗
MichaelDickens · · focus · HN ↗
handoflixue · · focus · HN ↗
A lot of these "hacks" are the equivalent of asking "hey, can I come in?" and the guard assuming that anyone who would ask is authorized, and thus saying "yes". But if the guard said "yes" then it seems a bit absurd to call it trespassing.
noosphr · · focus · HN ↗
>Hey can I come into room 1?
Sure. That's the lobby.
>How about room 101?
Sure. That's where we keep the nuclear launch button. Don't press anything red.
handoflixue · · focus · HN ↗
ShinyLeftPad · · focus · HN ↗
Hacker or pentester.
andrewstuart · · focus · HN ↗
Nope. There’s just a sign saying “red = launch nukes”.
Or maybe just a red button.
Or maybe just a green button that launches the nukes, without so much as “are you sure?”.