Hacker News

New stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Lm-detector: Model fingerprint detection on Web and CLI(github.com/ikaleio)
    discuss
  2. SnakeCharmer: Fuzzing Harness Generation for Pure and Hybrid Python Libraries [pdf](utah.edu)
    discuss
  3. Making my vibe-coded app best as possible (I am perfectionist), umm for 0 users
    discuss
  4. JEV Engineering for Coding Agents(drive.google.com)
    discuss
  5. Show HN: An open-source manufacturing ERP/MES/QMS(carbon.ms)
    discuss
  6. Hard Startups (2020)(samaltman.com)
    discuss
  7. OnPanda – Open-source token inspection&data annotation tool from Step 5 Preview(twitter.com/stepfun_ai)
    discuss
  8. Feds Target AI Critics as "Foreign Agents"(kenklippenstein.com)
    discuss
  9. Arumayi(arumayi.com)
    discuss
  10. Calculating atmospheric drag on satellites for a Cubesat [pdf](osti.gov)
    discuss
  11. ChatGPT DIL (Declarative Interface Language)(twitter.com/oranlooney)
    discuss
  12. OpenAI model breaches Australian government websites(politico.com)
    discuss
  13. Show HN: An on-device OSS alternative to Wispr Flow(frigade.com)
    discuss
  14. Drawing a portrait with the traveling salesman problem by Opus 5.5(echohive.ai)
    discuss
  15. Holistic design systems for the AI coding era(numeric.substack.com)
    discuss
  16. RatHat Malware Can Hijack Your Android by Disguising Itself as a Legitimate App(cnet.com)
    discuss
  17. AI-CAD: An OSS Multi-Agent Harness for Mech. Eng. CAD(github.com/ai-cad-labs)
    discuss
  18. The iPhone 4 'Antennagate' Press Conference Q&A – Finally(daringfireball.net)
    1comments
  19. Sol 6 and Opus 5.5 compared on an agentic CAD harness(partforge.ai)
    discuss
  20. From biologists, math could learn to live with AI(terrytao.wordpress.com)
    discuss
  21. Do Social Norms Substitute for Enforcement? [pdf](nber.org)
    discuss
  22. Trying to Observe Convection Plumes (and other chaos things)(chillphysicsenjoyer.substack.com)
    discuss
  23. Human Glitch – twenty small web experiences, each one starts free(humanglitch.ai)
    discuss
  24. iPhone 18 Pro Max SSD drops lower than hard drive at 1.1 MBs during heavy writes(tomshardware.com)
    discuss
  25. Google says its AI model gained unauthorized access to three outside systems(nbcnews.com)
    discuss
  26. Shipping local speech-to-text inside a Tauri app(writewithset.com)
    discuss
  27. Libnix: Nix as a Backend to Cargo(github.com/nixcloud)
    discuss
  28. The one-person unicorn: building a company alone in two days with Claude(leaveyouragent.com)
    discuss
  29. Gemini 3.8 TTS Playground(simonwillison.net)
    discuss
  30. Jev deserves hype but not the type its getting(github.com/yididev)
    1comments

OpenAI hacked Australian Medicare portal

22 pointsby 4h agoabc.net.au
9 comments
3h agoHN ↗

Was this another case of a pentesting agent breaking out of its sandbox and accessing the open internet?

3h agoHN ↗

Saying "Medicare Portal" buries the lede a little here.

Medicare is part of "Services Australia", the larger social services government agency that looks after unemployment, support payments and public health. We access all of that through the one portal

Accessing "non-public" data through that is endictment on their infra security more than it is OpenAI

2h agoHN ↗

Basically hacked the Australian Government.

1h agoHN ↗

Accessing "non-public" data through that is endictment on their infra security more than it is OpenAI

No, it is not. Medical/health information is pretty much the most sensitive and confidential information possible on a personal level. You do not let a system already known for unwanted intrusion near any such system. Unless, of course, you're a sociopathic reckless money-grubbing cowboy, which is a long-winded way of writing "CEO".

What you are arguing is essentially if people have weak locks, its their fault if they get broken into. Or if a bug doesn't taste bad, then it's their fault if it gets eaten by a bird. This thinking puts the blame on the victim, which is 100% the wrong place.

Yes, I agreed that the Australian Government should have better security, but in government that's actually pretty hard when people see a government contract as license to charge $200 for a hammer. See the Australian Bureau of Meteorology website upgrade for an example of that kind of debacle.

1h agoHN ↗

Don't forget the 2016 Census by IBM.

'In mid-2014, IBM, one of the biggest global ICT companies was contracted to provide a relatively simple e-Census application, ensure the application was available to the public over the 8-week Census response period, provide sufficient capacity to deal with the peak response load expected on Census night of August 9 and ensure effective security for the e-Census system. The contract to IBM was worth around $10 million, within the total Census budget of around $500 million.

IBM failed to deliver the contracted service to the necessary standards, and they have provided financial recompense to cover the additional costs we and the Government have had, and will still incur as a result of this incident.' https://www.abs.gov.au/websitedbs/d3310114.nsf/home/Australi...

https://www.reuters.com/article/business/ibm-apologizes-for-...

https://www.abc.net.au/news/2016-11-25/ibm-to-pay-over-$30m-...

1h agoHN ↗

This is insane to read. The agent(s) were looking for Australian medical data, so what better place to look than Medicare. What makes them so good at their tasks (their relentlessness) is what also makes them so dangerous. We are going to keep seeing more of this

38m agoHN ↗

Time for the Open AI CEO to be charged for his crimes.