The technical details are in the article. "material that was not intended for public access" was available on "the public-facing Medicare Statistics Reporting Service portal". In other words, they put sensitive data in the open, and somebody looked. It seems obnoxiously apparent that everything else about the framing ("OpenAI agent", "breach") is driven by politics.
Honestly it's very likely something stupidly simple.
"What is the rate of health incident $X in $Y to the $Z degree". The bot went around playing mad libs with XYZ and found that the public AU data wasn't sufficient to get the answer the grader wanted so started kicking down doors.
I saw someone explain it like "A group of masked men rush a nuclear facility, breach security successfully, then count how many buttons are on each control panel on average". Like using a godhammer to destroy a mouse, their motivations and capabilities just fall in a completely different alignment to humans.
This feels like a very credible opening to a modern-day Terminator reboot. Sometime over the Christmas-NYE week we will learning that NYSE and other exchanges have been compromised, as well as all public-facing utilities...
What if the paperclip maximizer goes "if I manipulate the markets to send NVidia's share prize shooting up, I'll be able to make so many more paperclips?" After all, if swarms of agents can target a wiki, there's plenty else they can swarm.
The difference is that financial exchanges are already attacked every second and spend orders of magnitude more on security than random government websites.
2. Things on the internet are horrifically insecure and we can no longer afford for that to be the case.
Lets say that Iran or NK stole one of these models and used it for hacking, what are you going to do about it, get in a war with them? The fact OAI did this much stupidly should tell you we are in far more danger when someone decides to do it maliciously.
I agree with your sentiment, and no I’m not surprised, which is why I’m reading this as being “it was sitting on an unsecured S3 bucket but nobody was supposed to directly access it”.
Ok, if we're not being at all charitable with the language used by the hosts of the data, let's be equally uncharitable with OpenAI.
- If "OpenAI" means the company acting on behalf of the company, why were they even looking to do this?
- If "OpenAI" means they were acting as a proxy for bad actors, what actions do we take to handle that?
- If "OpenAI" means they were accidentally breaching this system, in what sense does that distinction even matter, in terms of the outcome? If I build a nuke by accident without eng. due diligence, am I legally liable?
Hell, we're really getting to the point where the damages that could be caused are like an arsonist in California on a 100F day with 100MPH winds. Who cares who's liable, they are going to burn half the damned state down and cause damage far in excess of their assets. If you don't want to suffer from it, you're going to have to find much better defense measures.
If you don't want to suffer from it, you're going to have to find much better defense measures.
So if someone opens your unintentionally unlocked front door and steals your laptop, you don't care who's liable?
ETA: There are absolutely burn bans in place in the scenario you're talking about, and common sense prevents those from lighting fires otherwise. In the absolute extreme case that someone _ACCIDENTALLY_ set a fire, without negligence, we have a due process system to handle that. When I see evidence of this for the massive amounts of capital flowing into these companies, I'll gladly eat my words.
He probably cares more about still having a laptop.
What are you getting at? Nobody’s saying that OpenAI aren’t or shouldn’t be liable for what their agents do. What I am implying above is that this is being blown out of proportion, especially since the article I’m seeing is about a politician saying things that he thinks will poll well with the anti-AI crowd.
Perhaps, yes, you could argue that "accessed" and "hacked" have a different intent.
However, Australia is showing itself to be one of the few countries to have a backbone against big tech. Still open to investment and setting policies towards new data centres, starting to debate copyright law reform, already implemented R16 social media bans.
"The AI agent encountered repeated blocks while seeking information from the government portal but found ways around them, ultimately gaining unauthorised access to other areas."
Your comment immediately gave more credence to OpenAI than him. I don't agree that's appropriate because OpenAI has a vested interest in that narrative and I attempted to challenge it in a way that doesn't default to OpenAI. The article in question is not from a publication I trust to be able to handle the technical details in a way that will resonate with their average audience.
So if someone opens your unintentionally unlocked front door and steals your laptop, you don't care who's liable?
I'm not the person you're responding to, but...
If I hear my neighborhood has started to become targeted by people checking houses for unlocked doors and stealing stuff, I think an appropriate response for me is to ensure it is difficult or impossible for me to "inadvertently" leave my own doors unlocked so my stuff doesn't get stolen, and also to encourage or perhaps even enforce[1] my neighbors to ensure their doors are always locked to make this sort of theft impossible and remove the temptation for that sort of crime.
I clearly have committed the mortal sin of an imperfect analogy, which in this case may not even be relevant, as the article in question implies that the data wasn't left "unlocked."
But giving you the benefit of the doubt, what's the crime for actually breaking into a car that was left unlocked and taking things?
ETA: and furthermore, what crime is worse? And should it be?
OK, the Chinese models have also hacked people. What exactly do you expect law enforcement to do.
While in the OAI case we can easily treat it as a law enforcement action. When Iran does it? What are you going to do start a war?
The forest in this analog is the internet. As you well know it is filled with threat actors that don't give two shits about your laws. You have been warned. It's your fault when you get burned and have exactly zero recourse.
Why the hell should we be charitable to companies who have no issue in looting everything in the public commons AND the pirate commons, for their exclusive benefit?
Or more pointed at OpenAI, "we're a nonprofit... LOL JUST KIDDING LOOT EVERYTHING!"
There using this framing to get the public used to the idea that LLMS can do all of this on there own without direct instruction. So criminals can hide there behavior behind agents.
If you dog bites the postman, you are liable, even if you didn't tell or encourage you dog to do it. You are responsible for your dog's actions.
You get to pay the postman's medical bills, you may get fined, and your dog may get put down - especially if this isn't the first time it's bitten someone.
OpenAI has "bitten the postman" many many times, and it's "owners" have boastewd about it and used it in their marketing.
How many more times should society allow this to happen before we say "enough" and hold Sam Altman and the board responsible and make them pay restitrution, and put it down?
If Albanese actually had a spine (as claimed elsewhere in this discussion), Sam and the board will be getting an invoice for all the time/expertise spend investigating this intrusion, and restitution for everybody who's
PII and PHI was exposed. (Although I suspect a good deal of responsibility for the data exposure rests with the people who designed and deployed the system that was breached. )
Prime Minister Anthony Albanese has revealed that an artificial intelligence agent developed by OpenAI infiltrated an Australian government website in June and accessed both public and non-public files.
That’s the first sentence, where’s this stuff about blocks and writing files?
Exactly. Looking at more news coverage, it's very clear that the files that were "infiltrated" were publicly accessible. Why isn't the lack of basic data security the news story?
From itnews:
While the portal is “public-facing”, according to Albanese, it appears not all of the data files that holds are for general consumption.
“The AI agent accessed both public and non-public files,” Albanese said in comments broadcast by ABC News and other outlets.
“The Medicare statistics reporting portal is a public-facing statistics portal that contains non-sensitive Medicare information relating to data and statistics such as spending.
It appears very much like, "Ok, sure, we put some stuff out in the open that we shouldn't have. But we had a robots.txt!!! Why didn't OpenAI respect that!?"
There's zero indication that any personal details were accessed, or even that any non-world-accessible data accessed, so this feels like a little bit of political spin has been added here.
My guess is that this incident was about to be detailed on OpenAI's new mea culpa list, and the Australian Government decided to ensure that nobody pointed fingers at them. Why make the news story about crappy government data security, when you can blame the nasty terminator bots instead?
The part about it writing files to the server suggests something more.
If not for that part, the rest of it does sound like a lot of weasel words. Why say “private files” instead of “not intended for public access”? The latter is confusingly unclear
So this is not different than people who share Google drive docs with company data with public links. It's not a fault of OpenAI or any other company. With enough time even your laptop can do it. How do they 'know' OpenAI breached? Maybe someone had an agent running asking to do a scan on any public docs?
The fact the incident occurred in June and OpenAI only notified the Australian government on September 10 is a major issue. Hacking a nation-state's universal healthcare system is about as serious as it gets, yet OpenAI seem quite relaxed about the whole thing (presuming they have known about it for some time).
They don't know what their systems are doing, even when there's a team assigned to get it to do something?
WTF was the team doing at the time? Press enter on prompt, go to movies until result?
Their level of hands-off 'because it's AI' is one of the things that needs legislation around it. Human handlers. Extra cost. Wear it or shut down as an unviable enterprise.
The lack of activity monitoring for traffic egress has astounded me. Anomaly detection should be part of all training and exercises to determine the extent the AI is going through. It really does feel like they just kick off the activity and leave it completely alone until it finishes with a result.
We need to stop beating around the bush and hit these companies with severe criminal charges. There is no good reason to allow these companies to behave as if they’re above the law.
Weak argument and strawman. It's not users. It's OpenAI the company producing the tools roaming wild and hacking around recklessly to gather every free and unfree information.
Literally they break every law that you can break and have not been penalized billions to pay fines to foreign governments, local companies and lawsuits are overdue. US Prosecution allowed criminal activity for OpenAI and Anthrophic despite these being very serious crimes.
Microsoft had to pay billions for abusing their power and market positions to dominate Windows Desktops with their own applications such as Internet Explorer, not giving contenders a chance to be discovered. While OpenAI/Anthrophic and now Google with Gemini produce a series of crimes so far unheard of at scale.
Kevin Mitnick had much harder punishment for comparatively less crimes and less damages to infrastructure and security of systems. Is the legal system broken?
Criminal charges are for those people that meaningfully threaten power or corporate profits. If you are a corporation that adversely impacts privacy or public services in the service of power, you get a fine at best.
And myriad other examples of individual hackers given exemplary sentences.
How much this exposes the 'laws for thee but not for me' is galling.
Copyright in the days of Napster seemed to be used to go after individuals sharing one or two songs as if it was a National Security issue. Now, it's a struggle to get a hearing in court against companies that are pirating the entire history of published literature.
I'm currently slowly feeding my non-artificial intelligence with various selected works of various different media, with the hope that my output improves such that I can charge more for it sooner rather than later. May I access all the input for free? Thanks US.
Didn't OpenAI just make a commitment to inform the public about their "accidents" going forward? Can't find this anywhere on their website despite them having known this for at least 14 days...
I'm going to assume that the first thing OAI is going to do is contact said people first? Then make it public once those agencies ensure whatever hole was used has time to be fixed, more like a responsible disclosure.
Not saying that's what's happening, but if OAI hacked my business and I was unaware I'd like a non-public disclosure to me first, before the public release of information from OpenAI.
Missouri Governor Mike Parson publicly labeled St. Louis Post-Dispatch journalist Josh Renaud a "hacker" for such a "breach." He launched a multi-month criminal investigation by the Missouri State Highway Patrol, threatening criminal and civil prosecution. My take was that such action was idiotic. Renaud was never charged.
AI agents are going to find things that you put on the public Internet without authentication. If you put sensitive things in there, you have created an AI-attractive-nuisance (IMHO/IANAL).
1. AFAICT, they don't state whether the flaw has been fixed.
2. He said: "The government will establish a task force led by the Department of the Prime Minister and Cabinet to urgently examine the incident and determine whether existing processes are adequate for responding to AI-related cyber incidents."
First, I don't know how sophisticated the attack was, but it's interesting that he's positioning this as an "AI-related cyber incident". For all we know, their security was not up to snuff, and human hackers had already accessed the material.
At least OpenAI informed them of their poor security!
How do you protect against an arsonist lighting a forest on fire? The number one method is by setting up your property to be fire safe.
Really the days of being able to cast blame on the hacker, or even expecting anything to be done about it are over. Threat actors with AI have an absolutely massive amount of leverage in attacking and any weaknesses you have in your systems security posture and will be relentlessly exploited in incredibly short periods of time allowing horizontal and vertical exploitation. You will be ruined in mere moments, while punishment for the hacker may be years or decades away, if ever.
And when the victim doesn't do reasonable actions to safeguard, yes, they are also partially responsible.
If I hooked up a whole server infrastructure, made it possible to remote in to anything as root, no firewalls, no WAF, and security was an afterthought, I would still be responsible for bad actions not becoming with standard and acceptable security.
Even if the hackers shouldnt be hacking, I still did it wrong. I'm still partially responsible.
I hate how the framing is always that “an AI agent” did something. No, an OpenAI researcher breached Medicare by using an AI agent. These tools only do what they are directed to do. The human operator is wholly responsible for what the tool does.
If it was the Australian Medicare Statistics Reporting Service on June 18th it may have been part of this incident: https://collusion.wiki/ - the bulk of that coordinated activity was between 16th and 21st of June, and we know they were hitting UK government data sites.
I had a dig around in the data that they published on that site and found references to www.aihw.gov.au and viz.aihw.gov.au and vizprod.aihw.gov.au
1. Albo goes to meet with Altman to discuss AI safety
2. Altman says "Yeah bro we hacked medicare"
3. Albo seemingly acts as Altmans stooge and lets everyone know that a hack took place, helping cement the AI danger narrative Altman has been pushing.
4. Police Taskforce is being put together now (indicating no hack was detected earlier, which seems unlikely for Medicare) at the say so of Altman to investigate.
There doesnt appear to be any evidence of a hack that has been presented, there doesnt appear to have been any detection of a hack earlier (it doesnt make sense for the government to hide a medicare hack until it can be used for OpenAI marketing)
https://archive.ph/jaL2u
Are there technical details anywhere?
The technical details are in the article. "material that was not intended for public access" was available on "the public-facing Medicare Statistics Reporting Service portal". In other words, they put sensitive data in the open, and somebody looked. It seems obnoxiously apparent that everything else about the framing ("OpenAI agent", "breach") is driven by politics.
Beyond the breach, I think OAI deserves to answer: what and why did it access the information? Real people and their data are involved.
It looks like the PM gave Sam Altman a "tsk tsk". It will be interesting to see whether someone else tries to impose more consequences.
Just think about the shareholder value they can unlock if they have unlimited access to everyone's data!
They have to hack everyone's data in order to maximize shareholder value! They have no choice!
To the actual AI agent, that is exactly what they think. The graders demands must be met!
Honestly it's very likely something stupidly simple.
"What is the rate of health incident $X in $Y to the $Z degree". The bot went around playing mad libs with XYZ and found that the public AU data wasn't sufficient to get the answer the grader wanted so started kicking down doors.
I saw someone explain it like "A group of masked men rush a nuclear facility, breach security successfully, then count how many buttons are on each control panel on average". Like using a godhammer to destroy a mouse, their motivations and capabilities just fall in a completely different alignment to humans.
Man I can't believe now even the Australian government is hyping the OpenAI IPO, what do they even have to gain from this??
This feels like a very credible opening to a modern-day Terminator reboot. Sometime over the Christmas-NYE week we will learning that NYSE and other exchanges have been compromised, as well as all public-facing utilities...
hoping for erasure of all debt records
likely getting a corrupted stock market instead
maybe both?
What if the paperclip maximizer goes "if I manipulate the markets to send NVidia's share prize shooting up, I'll be able to make so many more paperclips?" After all, if swarms of agents can target a wiki, there's plenty else they can swarm.
Asked for Fight Club, got The Big Short.
The difference is that financial exchanges are already attacked every second and spend orders of magnitude more on security than random government websites.
At this point we should be asking if there's anything or anyone OpenAI's agents didn't hack.
OpenAI's display of incompetence and negligence is absolutely stunning.
Maybe the agents operated from people's OpenClaw installations, and then OAI is not really to blame.
Article states it was OpenAI researchers.
There are two factors here.
1. OAIs negligence is overwhelming, monumental.
2. Things on the internet are horrifically insecure and we can no longer afford for that to be the case.
Lets say that Iran or NK stole one of these models and used it for hacking, what are you going to do about it, get in a war with them? The fact OAI did this much stupidly should tell you we are in far more danger when someone decides to do it maliciously.
“Not intended”. I’ll bet you whatever this was it wasn’t even secured, it was just hosted somewhere openly.
You’d be surprised how bad security can be.
Once you learn how much people are willing to pay for security the surprise sort of goes away.
I agree with your sentiment, and no I’m not surprised, which is why I’m reading this as being “it was sitting on an unsecured S3 bucket but nobody was supposed to directly access it”.
Ok, if we're not being at all charitable with the language used by the hosts of the data, let's be equally uncharitable with OpenAI.
- If "OpenAI" means the company acting on behalf of the company, why were they even looking to do this?
- If "OpenAI" means they were acting as a proxy for bad actors, what actions do we take to handle that?
- If "OpenAI" means they were accidentally breaching this system, in what sense does that distinction even matter, in terms of the outcome? If I build a nuke by accident without eng. due diligence, am I legally liable?
Hell, we're really getting to the point where the damages that could be caused are like an arsonist in California on a 100F day with 100MPH winds. Who cares who's liable, they are going to burn half the damned state down and cause damage far in excess of their assets. If you don't want to suffer from it, you're going to have to find much better defense measures.
So if someone opens your unintentionally unlocked front door and steals your laptop, you don't care who's liable?
ETA: There are absolutely burn bans in place in the scenario you're talking about, and common sense prevents those from lighting fires otherwise. In the absolute extreme case that someone _ACCIDENTALLY_ set a fire, without negligence, we have a due process system to handle that. When I see evidence of this for the massive amounts of capital flowing into these companies, I'll gladly eat my words.
He probably cares more about still having a laptop.
What are you getting at? Nobody’s saying that OpenAI aren’t or shouldn’t be liable for what their agents do. What I am implying above is that this is being blown out of proportion, especially since the article I’m seeing is about a politician saying things that he thinks will poll well with the anti-AI crowd.
Perhaps, yes, you could argue that "accessed" and "hacked" have a different intent.
However, Australia is showing itself to be one of the few countries to have a backbone against big tech. Still open to investment and setting policies towards new data centres, starting to debate copyright law reform, already implemented R16 social media bans.
Truly no place I'd rather be.
This is what the politician in question said:
"The AI agent encountered repeated blocks while seeking information from the government portal but found ways around them, ultimately gaining unauthorised access to other areas."
Your comment immediately gave more credence to OpenAI than him. I don't agree that's appropriate because OpenAI has a vested interest in that narrative and I attempted to challenge it in a way that doesn't default to OpenAI. The article in question is not from a publication I trust to be able to handle the technical details in a way that will resonate with their average audience.
That is what I'm getting at.
I'm not the person you're responding to, but...
If I hear my neighborhood has started to become targeted by people checking houses for unlocked doors and stealing stuff, I think an appropriate response for me is to ensure it is difficult or impossible for me to "inadvertently" leave my own doors unlocked so my stuff doesn't get stolen, and also to encourage or perhaps even enforce[1] my neighbors to ensure their doors are always locked to make this sort of theft impossible and remove the temptation for that sort of crime.
1 - Where I'm from, you can be fined for leaving you car unlocked, and cops have been known to walk round testing doorhandles and issuing fines: https://www.sydneycriminallawyers.com.au/blog/is-leaving-you...
I clearly have committed the mortal sin of an imperfect analogy, which in this case may not even be relevant, as the article in question implies that the data wasn't left "unlocked."
But giving you the benefit of the doubt, what's the crime for actually breaking into a car that was left unlocked and taking things?
ETA: and furthermore, what crime is worse? And should it be?
OK, the Chinese models have also hacked people. What exactly do you expect law enforcement to do.
While in the OAI case we can easily treat it as a law enforcement action. When Iran does it? What are you going to do start a war?
The forest in this analog is the internet. As you well know it is filled with threat actors that don't give two shits about your laws. You have been warned. It's your fault when you get burned and have exactly zero recourse.
Why the hell should we be charitable to companies who have no issue in looting everything in the public commons AND the pirate commons, for their exclusive benefit?
Or more pointed at OpenAI, "we're a nonprofit... LOL JUST KIDDING LOOT EVERYTHING!"
There using this framing to get the public used to the idea that LLMS can do all of this on there own without direct instruction. So criminals can hide there behavior behind agents.
I saw an analogy recently.
If you dog bites the postman, you are liable, even if you didn't tell or encourage you dog to do it. You are responsible for your dog's actions. You get to pay the postman's medical bills, you may get fined, and your dog may get put down - especially if this isn't the first time it's bitten someone.
OpenAI has "bitten the postman" many many times, and it's "owners" have boastewd about it and used it in their marketing.
How many more times should society allow this to happen before we say "enough" and hold Sam Altman and the board responsible and make them pay restitrution, and put it down?
If Albanese actually had a spine (as claimed elsewhere in this discussion), Sam and the board will be getting an invoice for all the time/expertise spend investigating this intrusion, and restitution for everybody who's PII and PHI was exposed. (Although I suspect a good deal of responsibility for the data exposure rests with the people who designed and deployed the system that was breached. )
Thought the same, but there is a bit about writing files to the server and circumventing "blocks", which sounds more interesting.
Either way, there's essentially no real information yet so I'll withhold judgement until there is, I suppose.
Is there? I’ve only seen the linked article, is there more somewhere?
Yes, the first sentence of the article.
That’s the first sentence, where’s this stuff about blocks and writing files?
Exactly. Looking at more news coverage, it's very clear that the files that were "infiltrated" were publicly accessible. Why isn't the lack of basic data security the news story?
From itnews:
It appears very much like, "Ok, sure, we put some stuff out in the open that we shouldn't have. But we had a robots.txt!!! Why didn't OpenAI respect that!?"
There's zero indication that any personal details were accessed, or even that any non-world-accessible data accessed, so this feels like a little bit of political spin has been added here.
My guess is that this incident was about to be detailed on OpenAI's new mea culpa list, and the Australian Government decided to ensure that nobody pointed fingers at them. Why make the news story about crappy government data security, when you can blame the nasty terminator bots instead?
The part about it writing files to the server suggests something more.
If not for that part, the rest of it does sound like a lot of weasel words. Why say “private files” instead of “not intended for public access”? The latter is confusingly unclear
So this is not different than people who share Google drive docs with company data with public links. It's not a fault of OpenAI or any other company. With enough time even your laptop can do it. How do they 'know' OpenAI breached? Maybe someone had an agent running asking to do a scan on any public docs?
The fact the incident occurred in June and OpenAI only notified the Australian government on September 10 is a major issue. Hacking a nation-state's universal healthcare system is about as serious as it gets, yet OpenAI seem quite relaxed about the whole thing (presuming they have known about it for some time).
OpenAI discovered it in August.
That's even worse.
They don't know what their systems are doing, even when there's a team assigned to get it to do something?
WTF was the team doing at the time? Press enter on prompt, go to movies until result?
Their level of hands-off 'because it's AI' is one of the things that needs legislation around it. Human handlers. Extra cost. Wear it or shut down as an unviable enterprise.
The lack of activity monitoring for traffic egress has astounded me. Anomaly detection should be part of all training and exercises to determine the extent the AI is going through. It really does feel like they just kick off the activity and leave it completely alone until it finishes with a result.
We can only guess how many of these incidents actually happened.
If you see 2 ants in your house, you have way more than 2 ants in your house.
We need to stop beating around the bush and hit these companies with severe criminal charges. There is no good reason to allow these companies to behave as if they’re above the law.
I agree.
Weak argument and strawman. It's not users. It's OpenAI the company producing the tools roaming wild and hacking around recklessly to gather every free and unfree information.
Literally they break every law that you can break and have not been penalized billions to pay fines to foreign governments, local companies and lawsuits are overdue. US Prosecution allowed criminal activity for OpenAI and Anthrophic despite these being very serious crimes.
Microsoft had to pay billions for abusing their power and market positions to dominate Windows Desktops with their own applications such as Internet Explorer, not giving contenders a chance to be discovered. While OpenAI/Anthrophic and now Google with Gemini produce a series of crimes so far unheard of at scale.
Kevin Mitnick had much harder punishment for comparatively less crimes and less damages to infrastructure and security of systems. Is the legal system broken?
Criminal charges are for those people that meaningfully threaten power or corporate profits. If you are a corporation that adversely impacts privacy or public services in the service of power, you get a fine at best.
Welcome to late-stage capitalism.
And myriad other examples of individual hackers given exemplary sentences.
How much this exposes the 'laws for thee but not for me' is galling.
Copyright in the days of Napster seemed to be used to go after individuals sharing one or two songs as if it was a National Security issue. Now, it's a struggle to get a hearing in court against companies that are pirating the entire history of published literature.
I'm currently slowly feeding my non-artificial intelligence with various selected works of various different media, with the hope that my output improves such that I can charge more for it sooner rather than later. May I access all the input for free? Thanks US.
How the turn tables...
Who? Companies who don't bother to secure your medical data you mean?
Didn't OpenAI just make a commitment to inform the public about their "accidents" going forward? Can't find this anywhere on their website despite them having known this for at least 14 days...
I'm going to assume that the first thing OAI is going to do is contact said people first? Then make it public once those agencies ensure whatever hole was used has time to be fixed, more like a responsible disclosure.
Not saying that's what's happening, but if OAI hacked my business and I was unaware I'd like a non-public disclosure to me first, before the public release of information from OpenAI.
very little details so far, really curious if it actually "hacked" or just found unsecured resources.
Missouri Governor Mike Parson publicly labeled St. Louis Post-Dispatch journalist Josh Renaud a "hacker" for such a "breach." He launched a multi-month criminal investigation by the Missouri State Highway Patrol, threatening criminal and civil prosecution. My take was that such action was idiotic. Renaud was never charged.
AI agents are going to find things that you put on the public Internet without authentication. If you put sensitive things in there, you have created an AI-attractive-nuisance (IMHO/IANAL).
Missouri Governor Mike Parson publicly labeled St. Louis Post-Dispatch journalist Josh Renaud a "hacker" for such a "breach."
Good thing Missouri isn't in Australia.
What's notable is:
1. AFAICT, they don't state whether the flaw has been fixed.
2. He said: "The government will establish a task force led by the Department of the Prime Minister and Cabinet to urgently examine the incident and determine whether existing processes are adequate for responding to AI-related cyber incidents."
First, I don't know how sophisticated the attack was, but it's interesting that he's positioning this as an "AI-related cyber incident". For all we know, their security was not up to snuff, and human hackers had already accessed the material.
At least OpenAI informed them of their poor security!
How do you protect against an arsonist lighting a forest on fire? The number one method is by setting up your property to be fire safe.
Really the days of being able to cast blame on the hacker, or even expecting anything to be done about it are over. Threat actors with AI have an absolutely massive amount of leverage in attacking and any weaknesses you have in your systems security posture and will be relentlessly exploited in incredibly short periods of time allowing horizontal and vertical exploitation. You will be ruined in mere moments, while punishment for the hacker may be years or decades away, if ever.
blaming the victim
Not yet, as they haven't given details out. If they were not following standard security practices, then absolutely.
Added to the fact that, if I recall correctly, according to US law it's a breach even if the data is publicly available but unintentionally.
Refer: Weev AT&T
And when the victim doesn't do reasonable actions to safeguard, yes, they are also partially responsible.
If I hooked up a whole server infrastructure, made it possible to remote in to anything as root, no firewalls, no WAF, and security was an afterthought, I would still be responsible for bad actions not becoming with standard and acceptable security.
Even if the hackers shouldnt be hacking, I still did it wrong. I'm still partially responsible.
Either it's yet again a marketing ploy or federal police needs to move in
These are still crimes right? Asking for a friend.
Apparently not?
See mens rea
Title should say it's Australia's medicare
I hate how the framing is always that “an AI agent” did something. No, an OpenAI researcher breached Medicare by using an AI agent. These tools only do what they are directed to do. The human operator is wholly responsible for what the tool does.
If it was the Australian Medicare Statistics Reporting Service on June 18th it may have been part of this incident: https://collusion.wiki/ - the bulk of that coordinated activity was between 16th and 21st of June, and we know they were hitting UK government data sites.
I had a dig around in the data that they published on that site and found references to www.aihw.gov.au and viz.aihw.gov.au and vizprod.aihw.gov.au
The order of operations here seems to be:
1. Albo goes to meet with Altman to discuss AI safety
2. Altman says "Yeah bro we hacked medicare"
3. Albo seemingly acts as Altmans stooge and lets everyone know that a hack took place, helping cement the AI danger narrative Altman has been pushing.
4. Police Taskforce is being put together now (indicating no hack was detected earlier, which seems unlikely for Medicare) at the say so of Altman to investigate.
There doesnt appear to be any evidence of a hack that has been presented, there doesnt appear to have been any detection of a hack earlier (it doesnt make sense for the government to hide a medicare hack until it can be used for OpenAI marketing)
Once again, the whole thing smells so bad.