‹ BackHN Continuity

Thread

OpenAI agent hacked Australian government website, PM says

256 points · 198 comments · rudy6912

  1. vintagedave · · focus · HN ↗
    > the breach took place on 18 June - Open AI informed the government with an email to a general address on 10 September

    So we have a company hacking a foreign government's websites and data. And, in terms of ethics, they take almost three months to notify; and in terms of competence, appear to have no formal contacts nor to have found one in that time.

    Once an American business starts hacking allied governments, it's time for strict responses, yes? Replace the governance (board and C-level)? Remove financial incentives and open the company - open weights, open training, per its original 'open' ethos?

    Altman is busy saying there needs to be regulation, but in terms of what OpenAI does, he can control that already.

    1. rot09 · · focus · HN ↗
      In the infosec community it is well known that OpenAI and Anthropic did not hire many security engineers or researchers pre-April 2026. There is likely a case for gross negligence (IANAL).

      There has been a crazy hiring push from both companies to poach security engineers/researchers from Google, Apple, and Meta since Q2/Q3, but the response was incredibly delayed. Many talented security engineers/researchers I know at Apple/Google/Meta (including myself) receiving these offers are worried about taking them due to the risks of criminal/personal liability and the more likely risk of tarnishing their careers.

      1. phoghed · · focus · HN ↗
        > There is likely a case for gross negligence.

        Do you have any legal expertise or is this pulled straight from your ass?

        1. rot09 · · focus · HN ↗
          Not a lawyer and this is not legal advice, but I did ask my lawyer about the potential personal risks after receiving an offer. I used that as a data point when I declined the offer and for my speculative comment.
          1. holmesworcester · · focus · HN ↗
            These details are fascinating, thank you for posting. Look at the structural problem they reveal.

            1. we have a substantial societal need to lock down powerful in-training AI

            2. many are calling for making these companies criminally liable for hacking

            3. security experts (like yourself) are turning down offers to help secure these systems in part because of potential liability

            This indicates that #2 might be the wrong response. Security professionals are like lawyers supposed to be paranoid and think worst-case. If you want top security professionals to secure these systems, we might need a culture of FAA-style blameless retro.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.