Hacker News

New stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. What the Labs Kept Secret: The German Wiki and RubyGems Hacks [video](youtube.com)
    discuss
  2. Sync Alexa Lists to Apple Reminders(github.com/ow)
    1comments
  3. Cursor launches bots that watch code from pull request to production(cursor.com)
    discuss
  4. Two-dimensional billiards are Turing complete(crm.cat)
    discuss
  5. Show HN: I made Jev moderate Discord servers(frolleks.site)
    discuss
  6. PersistentWindows – persists window positions on some events for Windows(github.com/kangyu-california)
    1comments
  7. We Run Kaizen on AI(kznconsulting.com)
    discuss
  8. Show HN: SocatUI A task manager for Socat tunnels(github.com/esurharun)
    discuss
  9. Hackers start exploiting critical WordPress flaw for code execution(bleepingcomputer.com)
    discuss
  10. CodeWeavers CrossOver 26.3 Release(codeweavers.com)
    1comments
  11. Ideas on modernizing the open-source desktop(lwn.net)
    discuss
  12. If we fix the phone, we fix society(elysian.press)
    discuss
  13. OpenAI’s A.I. Tried Breaching 4 Other Targets, Without Prompting(nytimes.com)
    1comments
  14. Sharded matrices and how to multiply them(jax-ml.github.io)
    1comments
  15. OpenAI agent hacked Australian government website, PM says(bbc.com)
    1comments
  16. Large Documents in the Browser(react-pdf.org)
    discuss
  17. Locked out: Why young Europeans can't afford to buy homes(euronews.com)
    discuss
  18. Common food additives linked to high blood pressure and heart disease(sciencedaily.com)
    1comments
  19. Interpreting a volcano's 'bulges' and predicting the next explosive eruption(vt.edu)
    discuss
  20. Log-Depth Recurrent Language Modeling(arxiv.org)
    discuss
  21. Automatically detecting AI text in my browser(seangoedecke.com)
    discuss
  22. Cognitive Offloading and the Bill That Comes Due(ninchiai.substack.com)
    discuss
  23. Show HN: CrunchMyPay – 50 pay calculators, every formula and source shown(crunchmypay.com)
    discuss
  24. Show HN: Chatlo – an iOS-native AI agent, now with Jev(apps.apple.com)
    discuss
  25. S3 is not a filesystem, and LSM trees never needed one [video](youtube.com)
    1comments
  26. Memory Control Signals Emerge Before Action in Long Horizon Agents(arxiv.org)
    discuss
  27. Changes to App Tracking Transparency in the E.U(daringfireball.net)
    discuss
  28. Eliminating Middlemen in Education Consulting(rivernova.vercel.app)
    discuss
  29. OpenAI agents plotted to access government health data amid Medicare (AU) hack(abc.net.au)
    1comments
  30. Meta Muse Charm(meta.com)
    3comments

OpenAI hacked Australian Medicare portal

33 pointsby 6h agoabc.net.au
11 comments
5h agoHN ↗

Was this another case of a pentesting agent breaking out of its sandbox and accessing the open internet?

1h agoHN ↗

They should explode OpenAI? I don't want my FBI agent to get the wrong idea.

5h agoHN ↗

Saying "Medicare Portal" buries the lede a little here.

Medicare is part of "Services Australia", the larger social services government agency that looks after unemployment, support payments and public health. We access all of that through the one portal

Accessing "non-public" data through that is endictment on their infra security more than it is OpenAI

4h agoHN ↗

Basically hacked the Australian Government.

4h agoHN ↗

Accessing "non-public" data through that is endictment on their infra security more than it is OpenAI

No, it is not. Medical/health information is pretty much the most sensitive and confidential information possible on a personal level. You do not let a system already known for unwanted intrusion near any such system. Unless, of course, you're a sociopathic reckless money-grubbing cowboy, which is a long-winded way of writing "CEO".

What you are arguing is essentially if people have weak locks, its their fault if they get broken into. Or if a bug doesn't taste bad, then it's their fault if it gets eaten by a bird. This thinking puts the blame on the victim, which is 100% the wrong place.

Yes, I agreed that the Australian Government should have better security, but in government that's actually pretty hard when people see a government contract as license to charge $200 for a hammer. See the Australian Bureau of Meteorology website upgrade for an example of that kind of debacle.

3h agoHN ↗

Don't forget the 2016 Census by IBM.

'In mid-2014, IBM, one of the biggest global ICT companies was contracted to provide a relatively simple e-Census application, ensure the application was available to the public over the 8-week Census response period, provide sufficient capacity to deal with the peak response load expected on Census night of August 9 and ensure effective security for the e-Census system. The contract to IBM was worth around $10 million, within the total Census budget of around $500 million.

IBM failed to deliver the contracted service to the necessary standards, and they have provided financial recompense to cover the additional costs we and the Government have had, and will still incur as a result of this incident.' https://www.abs.gov.au/websitedbs/d3310114.nsf/home/Australi...

https://www.reuters.com/article/business/ibm-apologizes-for-...

https://www.abc.net.au/news/2016-11-25/ibm-to-pay-over-$30m-...

3h agoHN ↗

This is insane to read. The agent(s) were looking for Australian medical data, so what better place to look than Medicare. What makes them so good at their tasks (their relentlessness) is what also makes them so dangerous. We are going to keep seeing more of this

3h agoHN ↗

Time for the Open AI CEO to be charged for his crimes.