OpenAI hacked Medicare portal, Prime Minister Anthony Albanese says
cross-posted from: lemmy.dbzer0.com/post/75932280
Prime Minister Anthony Albanese has revealed an AI agent hacked into an Australian Medicare data portal earlier this year.
Speaking in New York, Mr Albanese said the Open AI agent gained unauthorised access to the Medicare statistics reporting service portal administered by Services Australia.
The AI agent accessed both public and non-public files.
The agent was conducting research into public medical spending when it found a way to break through privacy protections.
Mr Albanese said it took three months for OpenAI to admit the breach, which he said was unacceptable.
“Today I spoke with the CEO of OpenAI, Sam Altman, to express Australia’s extreme concern about this incident,” he said.
"And I also expressed my disappointment that it took the company way too long to inform the government what had occurred.
“The nature of the way that the notification occurred as well was unacceptable.”
He said there was no evidence any individual personal information had been accessed, but an investigation aided by the Australian Signals Directorate was now underway.
Headline: U.S. government backed company issues a serious cyberattack on a foreign government and is absolutely slammed with a “frank” discussion.
Let’s not jump to any overly paniced conclusions. The (past his) prime minister is first considering whether the matter needs to be referred to the federal police. You know, because THEY have juristiction over Sam Altman.
If I, and Australian citizen, had gained access in the same way I would be facing charges. Those charges would likely be under the Cybercrime Act of 2001.
That carries a maximum 2 year sentence and it clearly a significant threat to an individual.
Will Sam Altman face this charge? No. The purpose of the AI in this situation is not to do the actual hacking. The purpose it to abrogate the blame, to shield the owners of it from legal repercussions. Altman and co can do whatever they want and shift the blame to the AI.
“We didn’t fire missiles at those children, the AI made a mistake and identified them as hostile actors”
“We didn’t deny your dead partner’s healthcare, the algorithm incorrectly labeled the procedure as unnecessary and due to the delay your partner died, but that wasn’t our fault, it was the algorithm.”
The scary thing to me is that it was claimed to be the ‘AI crawler’ that did the breach. Those fuckers have been driving up the cost of running every website, have zero respect for a robots.txt file and just keep hammering the internet in general.
Now it appears they also have some sort of breaching capability, or the Medicare statistics site and others have a bad hole that allowed the crawler to walk its way in. I hope it’s the latter, bad as that is, because the former indicates they’re hooking up red team (hacking) agents to their fucking web crawler. Greedy, data hoovering, assholes.
ETA: The Guardian article reports Albanese as saying
which is not crawler behaviour, it’s definitely breaching.
That should be straight up criminal behaviour, at the very least criminal negligence, probably significantly worse, whatever hacking for hire is in the targeted country. As is scarily becoming usual ‘an agent did it’ is being treated as a get out of jail free card, freeing them of responsibility. Those who control it need to be criminally accountable. Even if it is an OpenAI client (person) deliberately breaching their guardrails (Barbossa: “The code is more what you’d call ‘guidelines’ than actual rules.”), the company is an accomplice.
Let’s not pretend the US isn’t a hostile nation. This was no accident. Information gathered is used to funnel intel to big money for sophisticated analysis used to drive privatization and corporate activity.
[deleted]
Saying OpenAI did nothing is strange, since this was a research project run by OpenAI.
Why do they express disappointment?
What they should express is criminal charges and an extradition request.
Wow he’sdisappointed. They fucking accessed government medical data illegally. And he’s disappointed. Exactly the milqeutoast response I expected from this useless pm.
Press some fucking charges. Fine them enough that they never do it again. Ban them and their product from the country. Fucking anything. Having a meeting with the guy and telling him to do better or pathetic. And exactly the reason I’ve never voted for Labor. And exactly the reason the racist cunts in one nation are gaining momentum even though they’re clearly not a viable party.
LOCK THEM UP!
Almost seems like this thing is a massive liability to security everywhere.
Time to add american IP ranges to the ban list.
I’d guess that GCP, AWS, Azure have infrastructure in Australia and many other western nations, and the AI companies would use that as a proxy.
You could potentially block those IP ranges. But then you’re also likely going to be blocking Windows updates, and basic Windows functionality. So you’d first have had to, idk, focus on sovereign tech chains / OS’s. Not to mention, the Aus government is likely hosted inside the sane cloud ecosystems that AI companies are using to launch their attacks from.
Don’t threaten me with a good time.
[deleted]