OpenAI breaches Medicare, Albanese reveals

(smh.com.au)

73 points | by jonnonz 1 hour ago

14 comments

  • Lukas_Skywalker 48 minutes ago
  • mbgerring 14 minutes ago
    We need to stop beating around the bush and hit these companies with severe criminal charges. There is no good reason to allow these companies to behave as if they’re above the law.
  • Chance-Device 22 minutes ago
    > He said the agent had accessed files that were publicly available as well as material that was not intended for public access.

    “Not intended”. I’ll bet you whatever this was it wasn’t even secured, it was just hosted somewhere openly.

    • api 4 minutes ago
      You’d be surprised how bad security can be.
  • gravelc 18 minutes ago
    The fact the incident occurred in June and OpenAI only notified the Australian government on September 10 is a major issue. Hacking a nation-state's universal healthcare system is about as serious as it gets, yet OpenAI seem quite relaxed about the whole thing (presuming they have known about it for some time).
  • bonsai_spool 33 minutes ago
    This feels like a very credible opening to a modern-day Terminator reboot. Sometime over the Christmas-NYE week we will learning that NYSE and other exchanges have been compromised, as well as all public-facing utilities...
    • iAMkenough 19 minutes ago
      hoping for erasure of all debt records

      likely getting a corrupted stock market instead

      maybe both?

      • nxobject 14 minutes ago
        What if the paperclip maximizer goes "if I manipulate the markets to send NVidia's share prize shooting up, I'll be able to make so many more paperclips?" After all, if swarms of agents can target a wiki, there's plenty else they can swarm.
  • Topfi 9 minutes ago
    Didn't OpenAI just make a commitment to inform the public about their "accidents" going forward? Can't find this anywhere on their website despite them having known this for at least 14 days...
    • pixl97 2 minutes ago
      I'm going to assume that the first thing OAI is going to do is contact said people first? Then make it public once those agencies ensure whatever hole was used has time to be fixed, more like a responsible disclosure.

      Not saying that's what's happening, but if OAI hacked my business and I was unaware I'd like a non-public disclosure to me first, before the public release of information from OpenAI.

  • xbar 2 minutes ago
    Missouri Governor Mike Parson publicly labeled St. Louis Post-Dispatch journalist Josh Renaud a "hacker" for such a "breach." He launched a multi-month criminal investigation by the Missouri State Highway Patrol, threatening criminal and civil prosecution. My take was that such action was idiotic. Renaud was never charged.

    AI agents are going to find things that you put on the public Internet without authentication. If you put sensitive things in there, you have created an AI-attractive-nuisance (IMHO/IANAL).

    • reaperducer 0 minutes ago
      Missouri Governor Mike Parson publicly labeled St. Louis Post-Dispatch journalist Josh Renaud a "hacker" for such a "breach."

      Good thing Missouri isn't in Australia.

  • keithnz 7 minutes ago
    very little details so far, really curious if it actually "hacked" or just found unsecured resources.
  • nxobject 45 minutes ago
    Beyond the breach, I think OAI deserves to answer: what and why did it access the information? Real people and their data are involved.

    It looks like the PM gave Sam Altman a "tsk tsk". It will be interesting to see whether someone else tries to impose more consequences.

    • briga 26 minutes ago
      Just think about the shareholder value they can unlock if they have unlimited access to everyone's data!
  • RGS1811 17 minutes ago
    We can only guess how many of these incidents actually happened.
  • chrishare 46 minutes ago
    Are there technical details anywhere?
    • tobyjsullivan 10 minutes ago
      The technical details are in the article. "material that was not intended for public access" was available on "the public-facing Medicare Statistics Reporting Service portal". In other words, they put sensitive data in the open, and somebody looked. It seems obnoxiously apparent that everything else about the framing ("OpenAI agent", "breach") is driven by politics.
  • enraged_camel 32 minutes ago
    At this point we should be asking if there's anything or anyone OpenAI's agents didn't hack.

    OpenAI's display of incompetence and negligence is absolutely stunning.

    • amelius 28 minutes ago
      Maybe the agents operated from people's OpenClaw installations, and then OAI is not really to blame.
  • underyx 42 minutes ago
    Man I can't believe now even the Australian government is hyping the OpenAI IPO, what do they even have to gain from this??