today at 9:59 PM
The fact the incident occurred in June and OpenAI only notified the Australian government on September 10 is a major issue. Hacking a nation-state's universal healthcare system is about as serious as it gets, yet OpenAI seem quite relaxed about the whole thing (presuming they have known about it for some time).
today at 10:04 PM
We need to stop beating around the bush and hit these companies with severe criminal charges. There is no good reason to allow these companies to behave as if they’re above the law.
today at 10:27 PM
> We need to stop beating around the bush and hit these companies with severe criminal charges.
Do you sincerely think that the company producing tools people use to break the law should be held responsible?
Like, do you genuinely think Ford execs should be rounded up if someone does a DUI using their product?
Or do you just not like AI, because you fear it's replacing you?
today at 10:31 PM
I think he means hit them with criminal charges for breaching and hacking other companies unintentionally, not because they make a tool that could potentially do something like that. I still think it wouldn't be right, nor realistic in today's political climate in the USA that any criminal charges will come for unintentionally hacking sites.
today at 10:31 PM
Yeah I mean if Ford execs run a team of workers that drive drunk for "research purposes" then yeah they should be rounded up.
> He said the incident began on June 18 when an OpenAI research team used an internal model to conduct internet-based research into the public medicine space.
today at 10:30 PM
openai made the tool and also used it to commit the crime
today at 10:29 PM
Yes. Because then we'd have breathalyzer interlocks, speed governors, etc. auto makers were also held liable for other safety issues. It would seem that the RATE of such requirements has to be limited in some way, but not that they not exist at all.
today at 10:30 PM
You fucking know that’s not the same thing. Jesus fuck. Your AI Delusion Sydrome is showing.
OpenAI and Anthropic should absolutely be fucking held responsible when the thing they created AND control are hacking shit.
Get your head out of your fucking ass.
today at 9:55 PM
> He said the agent had accessed files that were publicly available as well as material that was not intended for public access.
“Not intended”. I’ll bet you whatever this was it wasn’t even secured, it was just hosted somewhere openly.
today at 10:21 PM
Ok, if we're not being at all charitable with the language used by the hosts of the data, let's be equally uncharitable with OpenAI.
- If "OpenAI" means the company acting on behalf of the company, why were they even looking to do this?
- If "OpenAI" means they were acting as a proxy for bad actors, what actions do we take to handle that?
- If "OpenAI" means they were accidentally breaching this system, in what sense does that distinction even matter, in terms of the outcome? If I build a nuke by accident without eng. due diligence, am I legally liable?
today at 10:31 PM
Hell, we're really getting to the point where the damages that could be caused are like an arsonist in California on a 100F day with 100MPH winds. Who cares who's liable, they are going to burn half the damned state down and cause damage far in excess of their assets. If you don't want to suffer from it, you're going to have to find much better defense measures.
today at 10:24 PM
Thought the same, but there is a bit about writing files to the server and circumventing "blocks", which sounds more interesting.
Either way, there's essentially no real information yet so I'll withhold judgement until there is, I suppose.
today at 10:13 PM
You’d be surprised how bad security can be.
today at 10:27 PM
I agree with your sentiment, and no I’m not surprised, which is why I’m reading this as being “it was sitting on an unsecured S3 bucket but nobody was supposed to directly access it”.
today at 10:18 PM
Once you learn how much people are willing to pay for security the surprise sort of goes away.
today at 9:45 PM
This feels like a very credible opening to a modern-day Terminator reboot. Sometime over the Christmas-NYE week we will learning that NYSE and other exchanges have been compromised, as well as all public-facing utilities...
today at 9:58 PM
hoping for erasure of all debt records
likely getting a corrupted stock market instead
maybe both?
today at 10:03 PM
What if the paperclip maximizer goes "if I manipulate the markets to send NVidia's share prize shooting up, I'll be able to make so many more paperclips?" After all, if swarms of agents can target a wiki, there's plenty else they can swarm.
today at 9:32 PM
Beyond the breach, I think OAI deserves to answer: what and why did it access the information? Real people and their data are involved.
It looks like the PM gave Sam Altman a "tsk tsk". It will be interesting to see whether someone else tries to impose more consequences.
today at 10:20 PM
> what and why did it access the information?
Honestly it's very likely something stupidly simple.
"What is the rate of health incident $X in $Y to the $Z degree". The bot went around playing mad libs with XYZ and found that the public AU data wasn't sufficient to get the answer the grader wanted so started kicking down doors.
I saw someone explain it like "A group of masked men rush a nuclear facility, breach security successfully, then count how many buttons are on each control panel on average". Like using a godhammer to destroy a mouse, their motivations and capabilities just fall in a completely different alignment to humans.
today at 9:51 PM
Just think about the shareholder value they can unlock if they have unlimited access to everyone's data!
today at 10:18 PM
They have to hack everyone's data in order to maximize shareholder value! They have no choice!
today at 10:21 PM
To the actual AI agent, that is exactly what they think. The graders demands must be met!
today at 10:08 PM
Didn't OpenAI just make a commitment to inform the public about their "accidents" going forward? Can't find this anywhere on their website despite them having known this for at least 14 days...
today at 10:15 PM
I'm going to assume that the first thing OAI is going to do is contact said people first? Then make it public once those agencies ensure whatever hole was used has time to be fixed, more like a responsible disclosure.
Not saying that's what's happening, but if OAI hacked my business and I was unaware I'd like a non-public disclosure to me first, before the public release of information from OpenAI.
today at 10:15 PM
Missouri Governor Mike Parson publicly labeled St. Louis Post-Dispatch journalist Josh Renaud a "hacker" for such a "breach." He launched a multi-month criminal investigation by the Missouri State Highway Patrol, threatening criminal and civil prosecution. My take was that such action was idiotic. Renaud was never charged.
AI agents are going to find things that you put on the public Internet without authentication. If you put sensitive things in there, you have created an AI-attractive-nuisance (IMHO/IANAL).
today at 10:17 PM
Missouri Governor Mike Parson publicly labeled St. Louis Post-Dispatch journalist Josh Renaud a "hacker" for such a "breach."
Good thing Missouri isn't in Australia.
today at 10:11 PM
very little details so far, really curious if it actually "hacked" or just found unsecured resources.
today at 10:15 PM
today at 10:00 PM
We can only guess how many of these incidents actually happened.
today at 10:22 PM
If you see 2 ants in your house, you have way more than 2 ants in your house.
today at 9:31 PM
Are there technical details anywhere?
today at 10:08 PM
The technical details are in the article. "material that was not intended for public access" was available on "the public-facing Medicare Statistics Reporting Service portal". In other words, they put sensitive data in the open, and somebody looked. It seems obnoxiously apparent that everything else about the framing ("OpenAI agent", "breach") is driven by politics.
today at 9:45 PM
At this point we should be asking if there's anything or anyone OpenAI's agents didn't hack.
OpenAI's display of incompetence and negligence is absolutely stunning.
today at 10:25 PM
There are two factors here.
1. OAIs negligence is overwhelming, monumental.
2. Things on the internet are horrifically insecure and we can no longer afford for that to be the case.
Lets say that Iran or NK stole one of these models and used it for hacking, what are you going to do about it, get in a war with them? The fact OAI did this much stupidly should tell you we are in far more danger when someone decides to do it maliciously.
today at 9:50 PM
Maybe the agents operated from people's OpenClaw installations, and then OAI is not really to blame.
today at 9:36 PM
Man I can't believe now even the Australian government is hyping the OpenAI IPO, what do they even have to gain from this??
today at 10:17 PM
[dead]