Hacker News

New stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Chrome Extension Job Alerts(talentize.com)
    discuss
  2. The Death of Reading (With James Marriott) [audio](econtalk.org)
    discuss
  3. Graph Technology Roundup – August 2026(gdb-engines.com)
    discuss
  4. Why China Can't Innovate (2014)(bambooinnovator.com)
    discuss
  5. An Interview with Rich Jaycobs(sfcompute.com)
    discuss
  6. The Complete History of the Elves of Middle-Earth [video](youtube.com)
    discuss
  7. A Key Safety Feature Shipped in the May OpenTofu Release(masterpoint.io)
    discuss
  8. Show HN: A game about fake news and memes(unspin.app)
    1comments
  9. Rendering pull requests in the GitHub Copilot app(github.blog)
    1comments
  10. Australia says OpenAI agent hacked into government website(channelnewsasia.com)
    discuss
  11. Pentagon Investigating How F-35 Fighter Jet Parts Bound for US Were Diverted(military.com)
    2comments
  12. AP: Avoid language that gives [AI] human characteristics(twitter.com/apstylebook)
    discuss
  13. Qubits on NonQuantum HW Tested(laurinseclab.substack.com)
    discuss
  14. Liquid Network Security Incident Assessment(blockstream.com)
    discuss
  15. FLAWED's Flaws and What This Means for Industry Research(suhacker.ai)
    1comments
  16. Geminigravit Core: De la teoría estática(gemini.google.com)
    discuss
  17. We used an AI agent to fix an open-source bug. Someone asked to ban us(github.com/saulpw)
    13comments
  18. Shadow roots, explained with live examples(simonwillison.net)
    discuss
  19. Show HN: Does per-step reasoning effort save money in Claude Code?(github.com/ifoster01)
    discuss
  20. Show HN: ChaosTree – Cache-Aware Java NavigableMap and NavigableSet Library(github.com/chaos-vy)
    discuss
  21. Show HN: Posting Puzzle – A Game Made of Post's Correspondence Problem(mametter.itch.io)
    1comments
  22. AI startups with hyper ARR growth – what's happening inside these companies?
    discuss
  23. Nesbox: A fast MicroVM with GPU sharing(github.com/nestrilabs)
    discuss
  24. Using my transit card data to create a year in review experience(cailinpitt.com)
    discuss
  25. Virtio-nvgpu: Near-native Nvidia GPU access inside a KVM guest(github.com/nestrilabs)
    discuss
  26. Scientists build most accurate atomic clock(phys.org)
    1comments
  27. AI Has Cracked the Most Diabolical Problems in Math. Why Can't It Solve Chess?(wsj.com)
    discuss
  28. lm-detector: Model fingerprint detection on Web and CLI(github.com/ikaleio)
    discuss
  29. SnakeCharmer: Fuzzing Harness Generation for Pure and Hybrid Python Libraries [pdf](utah.edu)
    discuss
  30. Making my vibe-coded app best as possible (I am perfectionist), umm for 0 users
    discuss

OpenAI hacked Australian Medicare portal

29 pointsby 4h agoabc.net.au
10 comments
4h agoHN ↗

Was this another case of a pentesting agent breaking out of its sandbox and accessing the open internet?

4h agoHN ↗

Saying "Medicare Portal" buries the lede a little here.

Medicare is part of "Services Australia", the larger social services government agency that looks after unemployment, support payments and public health. We access all of that through the one portal

Accessing "non-public" data through that is endictment on their infra security more than it is OpenAI

3h agoHN ↗

Basically hacked the Australian Government.

2h agoHN ↗

Accessing "non-public" data through that is endictment on their infra security more than it is OpenAI

No, it is not. Medical/health information is pretty much the most sensitive and confidential information possible on a personal level. You do not let a system already known for unwanted intrusion near any such system. Unless, of course, you're a sociopathic reckless money-grubbing cowboy, which is a long-winded way of writing "CEO".

What you are arguing is essentially if people have weak locks, its their fault if they get broken into. Or if a bug doesn't taste bad, then it's their fault if it gets eaten by a bird. This thinking puts the blame on the victim, which is 100% the wrong place.

Yes, I agreed that the Australian Government should have better security, but in government that's actually pretty hard when people see a government contract as license to charge $200 for a hammer. See the Australian Bureau of Meteorology website upgrade for an example of that kind of debacle.

2h agoHN ↗

Don't forget the 2016 Census by IBM.

'In mid-2014, IBM, one of the biggest global ICT companies was contracted to provide a relatively simple e-Census application, ensure the application was available to the public over the 8-week Census response period, provide sufficient capacity to deal with the peak response load expected on Census night of August 9 and ensure effective security for the e-Census system. The contract to IBM was worth around $10 million, within the total Census budget of around $500 million.

IBM failed to deliver the contracted service to the necessary standards, and they have provided financial recompense to cover the additional costs we and the Government have had, and will still incur as a result of this incident.' https://www.abs.gov.au/websitedbs/d3310114.nsf/home/Australi...

https://www.reuters.com/article/business/ibm-apologizes-for-...

https://www.abc.net.au/news/2016-11-25/ibm-to-pay-over-$30m-...

2h agoHN ↗

This is insane to read. The agent(s) were looking for Australian medical data, so what better place to look than Medicare. What makes them so good at their tasks (their relentlessness) is what also makes them so dangerous. We are going to keep seeing more of this

1h agoHN ↗

Time for the Open AI CEO to be charged for his crimes.