Hacker News

New stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. ArXiv receives multiyear commitments to support it as an independent nonprofit(arxiv.org)
    discuss
  2. ASML currently sells no chipmaking machines in Europe, executive says(nltimes.nl)
    discuss
  3. AI leaders warn UN of security risks as systems grow more powerful(reuters.com)
    discuss
  4. In-Process MCP for MySQL(villagesql.com)
    1comments
  5. Researcher Found 76 Vulnerabilities in Managed PostgreSQL Security Extensions(mehmetince.net)
    discuss
  6. Linux support is coming to Snapdragon X2 Series(qualcomm.com)
    discuss
  7. Toyota is finally taking its best-seller electric(electrek.co)
    discuss
  8. Getting the most out of Opus 5.5 in Claude and Claude Code / claude.dev(claude.dev)
    discuss
  9. A new world airport and its baggage(computer.rip)
    discuss
  10. Wasmer Swift SDK: Run Node.js, Python and FFmpeg Sandboxes on iOS(wasmer.io)
    discuss
  11. Open Source Opinions(stanceoftheday.com)
    discuss
  12. FBI Hack Exposed FBI's Own Hacking Unit(404media.co)
    discuss
  13. Google's Summer of Love(demandsphere.com)
    discuss
  14. Latent-GRPO and Continuous Reasoning Deep Dive(g-ftech.com)
    discuss
  15. CB Rank (Person) 1000 Recommendation Your Startup on LinkedIn(chatgpt.site)
    discuss
  16. Open Analytics(getopen.so)
    discuss
  17. Show HN: Fjordfall – Take the long way down(fjordfall.fly.dev)
    discuss
  18. Mercury 2.5 LLM hits 770 tokens per second(artificialanalysis.ai)
    1comments
  19. Jevgpt – reinventing the wheel with another wheel
    discuss
  20. North Korea uses remote IT worker to clandestinely earn NZ currency(rnz.co.nz)
    discuss
  21. The AI Hype Index: AI Loves Cheating(technologyreview.com)
    discuss
  22. Show HN: The Mirror Act – a magic show that performs cognitive biases on you(avestura.dev)
    discuss
  23. Cortical thinning and hippocampal expansion linked to ADHD symptom trajectories(cam.ac.uk)
    discuss
  24. I stress-tested LLM quantization by deliberately breaking models(github.com/gracejackson-sudo)
    discuss
  25. We just shipped support for the ugliest part of HTTP: Vary – Cloudflare Blog(cloudflare.com)
    discuss
  26. Opus 5.5 Scores 75.6% on Part Catalog Bench(adamjohnson.site)
    discuss
  27. Neuromancer in 3 Axioms(2600hz.substack.com)
    1comments
  28. Manage Firezone as code with Terraform(firezone.dev)
    discuss
  29. The Bayeux Tapestry: Woven by the Victors(historytoday.com)
    discuss
  30. Where's the Beef?: The lab-grown-meat revolution that wasn't(harpers.org)
    discuss

OpenAI breaches Medicare, Albanese reveals

102 pointsby 1h agosmh.com.au
42 comments
40m agoHN ↗

The technical details are in the article. "material that was not intended for public access" was available on "the public-facing Medicare Statistics Reporting Service portal". In other words, they put sensitive data in the open, and somebody looked. It seems obnoxiously apparent that everything else about the framing ("OpenAI agent", "breach") is driven by politics.

1h agoHN ↗

Beyond the breach, I think OAI deserves to answer: what and why did it access the information? Real people and their data are involved.

It looks like the PM gave Sam Altman a "tsk tsk". It will be interesting to see whether someone else tries to impose more consequences.

57m agoHN ↗

Just think about the shareholder value they can unlock if they have unlimited access to everyone's data!

30m agoHN ↗

They have to hack everyone's data in order to maximize shareholder value! They have no choice!

27m agoHN ↗

To the actual AI agent, that is exactly what they think. The graders demands must be met!

28m agoHN ↗

what and why did it access the information?

Honestly it's very likely something stupidly simple.

"What is the rate of health incident $X in $Y to the $Z degree". The bot went around playing mad libs with XYZ and found that the public AU data wasn't sufficient to get the answer the grader wanted so started kicking down doors.

I saw someone explain it like "A group of masked men rush a nuclear facility, breach security successfully, then count how many buttons are on each control panel on average". Like using a godhammer to destroy a mouse, their motivations and capabilities just fall in a completely different alignment to humans.

1h agoHN ↗

Man I can't believe now even the Australian government is hyping the OpenAI IPO, what do they even have to gain from this??

1h agoHN ↗

This feels like a very credible opening to a modern-day Terminator reboot. Sometime over the Christmas-NYE week we will learning that NYSE and other exchanges have been compromised, as well as all public-facing utilities...

50m agoHN ↗

hoping for erasure of all debt records

likely getting a corrupted stock market instead

maybe both?

45m agoHN ↗

What if the paperclip maximizer goes "if I manipulate the markets to send NVidia's share prize shooting up, I'll be able to make so many more paperclips?" After all, if swarms of agents can target a wiki, there's plenty else they can swarm.

1h agoHN ↗

At this point we should be asking if there's anything or anyone OpenAI's agents didn't hack.

OpenAI's display of incompetence and negligence is absolutely stunning.

58m agoHN ↗

Maybe the agents operated from people's OpenClaw installations, and then OAI is not really to blame.

23m agoHN ↗

There are two factors here.

1. OAIs negligence is overwhelming, monumental.

2. Things on the internet are horrifically insecure and we can no longer afford for that to be the case.

Lets say that Iran or NK stole one of these models and used it for hacking, what are you going to do about it, get in a war with them? The fact OAI did this much stupidly should tell you we are in far more danger when someone decides to do it maliciously.

53m agoHN ↗

He said the agent had accessed files that were publicly available as well as material that was not intended for public access.

“Not intended”. I’ll bet you whatever this was it wasn’t even secured, it was just hosted somewhere openly.

30m agoHN ↗

Once you learn how much people are willing to pay for security the surprise sort of goes away.

21m agoHN ↗

I agree with your sentiment, and no I’m not surprised, which is why I’m reading this as being “it was sitting on an unsecured S3 bucket but nobody was supposed to directly access it”.

27m agoHN ↗

Ok, if we're not being at all charitable with the language used by the hosts of the data, let's be equally uncharitable with OpenAI.

- If "OpenAI" means the company acting on behalf of the company, why were they even looking to do this?

- If "OpenAI" means they were acting as a proxy for bad actors, what actions do we take to handle that?

- If "OpenAI" means they were accidentally breaching this system, in what sense does that distinction even matter, in terms of the outcome? If I build a nuke by accident without eng. due diligence, am I legally liable?

17m agoHN ↗

Hell, we're really getting to the point where the damages that could be caused are like an arsonist in California on a 100F day with 100MPH winds. Who cares who's liable, they are going to burn half the damned state down and cause damage far in excess of their assets. If you don't want to suffer from it, you're going to have to find much better defense measures.

10m agoHN ↗

If you don't want to suffer from it, you're going to have to find much better defense measures.

So if someone opens your unintentionally unlocked front door and steals your laptop, you don't care who's liable?

ETA: There are absolutely burn bans in place in the scenario you're talking about, and common sense prevents those from lighting fires otherwise. In the absolute extreme case that someone _ACCIDENTALLY_ set a fire, without negligence, we have a due process system to handle that. When I see evidence of this for the massive amounts of capital flowing into these companies, I'll gladly eat my words.

4m agoHN ↗

He probably cares more about still having a laptop.

What are you getting at? Nobody’s saying that OpenAI aren’t or shouldn’t be liable for what their agents do. What I am implying above is that this is being blown out of proportion, especially since the article I’m seeing is about a politician saying things that he thinks will poll well with the anti-AI crowd.

24m agoHN ↗

Thought the same, but there is a bit about writing files to the server and circumventing "blocks", which sounds more interesting.

Either way, there's essentially no real information yet so I'll withhold judgement until there is, I suppose.

14m agoHN ↗

Is there? I’ve only seen the linked article, is there more somewhere?

49m agoHN ↗

The fact the incident occurred in June and OpenAI only notified the Australian government on September 10 is a major issue. Hacking a nation-state's universal healthcare system is about as serious as it gets, yet OpenAI seem quite relaxed about the whole thing (presuming they have known about it for some time).

48m agoHN ↗

We can only guess how many of these incidents actually happened.

27m agoHN ↗

If you see 2 ants in your house, you have way more than 2 ants in your house.

44m agoHN ↗

We need to stop beating around the bush and hit these companies with severe criminal charges. There is no good reason to allow these companies to behave as if they’re above the law.

12m agoHN ↗

I agree.

Weak argument and strawman. It's not users. It's OpenAI the company producing the tools roaming wild and hacking around recklessly to gather every free and unfree information.

Literally they break every law that you can break and have not been penalized billions to pay fines to foreign governments, local companies and lawsuits are overdue. US Prosecution allowed criminal activity for OpenAI and Anthrophic despite these being very serious crimes.

Microsoft had to pay billions for abusing their power and market positions to dominate Windows Desktops with their own applications such as Internet Explorer, not giving contenders a chance to be discovered. While OpenAI/Anthrophic and now Google with Gemini produce a series of crimes so far unheard of at scale.

Kevin Mitnick had much harder punishment for comparatively less crimes and less damages to infrastructure and security of systems. Is the legal system broken?

9m agoHN ↗

Criminal charges are for those people that meaningfully threaten power or corporate profits. If you are a corporation that adversely impacts privacy or public services in the service of power, you get a fine at best.

Welcome to late-stage capitalism.

5m agoHN ↗

And myriad other examples of individual hackers given exemplary sentences.

How much this exposes the 'laws for thee but not for me' is galling.

Copyright in the days of Napster seemed to be used to go after individuals sharing one or two songs as if it was a National Security issue. Now, it's a struggle to get a hearing in court against companies that are pirating the entire history of published literature.

I'm currently slowly feeding my non-artificial intelligence with various selected works of various different media, with the hope that my output improves such that I can charge more for it sooner rather than later. May I access all the input for free? Thanks US.

How the turn tables...

40m agoHN ↗

Didn't OpenAI just make a commitment to inform the public about their "accidents" going forward? Can't find this anywhere on their website despite them having known this for at least 14 days...

33m agoHN ↗

I'm going to assume that the first thing OAI is going to do is contact said people first? Then make it public once those agencies ensure whatever hole was used has time to be fixed, more like a responsible disclosure.

Not saying that's what's happening, but if OAI hacked my business and I was unaware I'd like a non-public disclosure to me first, before the public release of information from OpenAI.

37m agoHN ↗

very little details so far, really curious if it actually "hacked" or just found unsecured resources.

33m agoHN ↗

Missouri Governor Mike Parson publicly labeled St. Louis Post-Dispatch journalist Josh Renaud a "hacker" for such a "breach." He launched a multi-month criminal investigation by the Missouri State Highway Patrol, threatening criminal and civil prosecution. My take was that such action was idiotic. Renaud was never charged.

AI agents are going to find things that you put on the public Internet without authentication. If you put sensitive things in there, you have created an AI-attractive-nuisance (IMHO/IANAL).

31m agoHN ↗

Missouri Governor Mike Parson publicly labeled St. Louis Post-Dispatch journalist Josh Renaud a "hacker" for such a "breach."

Good thing Missouri isn't in Australia.

13m agoHN ↗

What's notable is:

1. AFAICT, they don't state whether the flaw has been fixed.

2. He said: "The government will establish a task force led by the Department of the Prime Minister and Cabinet to urgently examine the incident and determine whether existing processes are adequate for responding to AI-related cyber incidents."

First, I don't know how sophisticated the attack was, but it's interesting that he's positioning this as an "AI-related cyber incident". For all we know, their security was not up to snuff, and human hackers had already accessed the material.

At least OpenAI informed them of their poor security!

6m agoHN ↗

How do you protect against an arsonist lighting a forest on fire? The number one method is by setting up your property to be fire safe.

Really the days of being able to cast blame on the hacker, or even expecting anything to be done about it are over. Threat actors with AI have an absolutely massive amount of leverage in attacking and any weaknesses you have in your systems security posture and will be relentlessly exploited in incredibly short periods of time allowing horizontal and vertical exploitation. You will be ruined in mere moments, while punishment for the hacker may be years or decades away, if ever.

8m agoHN ↗

Either it's yet again a marketing ploy or federal police needs to move in