Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > aus.politics > #764100

Re: OpenAI hacks Medicare

From "Rod Speed" <rod.speed.aaa@gmail.com>
Newsgroups aus.politics, aus.computers, aus.cars
Subject Re: OpenAI hacks Medicare
Date 2026-09-25 09:27 +1000
Message-ID <op.3v6gsrl3byq249@pvr2.lan> (permalink)
References <260ce5e23ec30f0b858bf52481740730@dizum.com> <6ab5aac9@news.ausics.net>

Cross-posted to 3 groups.

Show all headers | View raw


Computer Nerd Kev <not@telling.you.invalid> wrote

> From OpenAI's statement
> "Our review found no evidence of patient records being accessed.
>  The information accessed included aggregate health statistics
>  and internal file names."

> "We notified the organisations and are providing technical
>  information to support their investigations and help address
>  potential security vulnerabilities"
> https://www.abc.net.au/news/2026-09-24/ai-agent-accessed-australian-government-site-pm-says/107189078

> "The government on Thursday launched a taskforce to investigate and
>  assess gaps in Australia's existing laws around reporting
>  requirements, enforcement, and cyber protections.

>  It is also investigating if the OpenAI incident broke any
>  Australian laws, though government sources said the initial view
>  was that this was unlikely."
> https://www.abc.net.au/news/2026-09-25/openai-breach-builds-case-for-tough-ai-rules/107192992

> Sounds like the AI just guessed some URLs that aren't linked from
> public pages, and got to see pages and directories that were really
> public in a technical sense anyway (not password protected by the
> server software).

Yep

> In that case it's not really a hack at all - just incompetent
> configuration of the website

Nothing incompetent give that data was always
intended for professional medical research and
not intended to be available to the general public

> which a human attacker would have
> easily found too if they saw a real motive to work on something as
> boring as a statistics "portal".

> No surprise the government is covering up this incompetance,

There is no incompetence

> which
> OpenAI highlighted to them, by beating their chest about the new
> powers of AI and boasting new regulations that are likely to be as
> weak as their websites.

Back to aus.politics | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

OpenAI hacks Medicare Nomen Nescio <nobody@dizum.com> - 2026-09-24 03:30 +0200
  Re: OpenAI hacks Medicare not@telling.you.invalid (Computer Nerd Kev) - 2026-09-25 08:57 +1000
    Re: OpenAI hacks Medicare "Rod Speed" <rod.speed.aaa@gmail.com> - 2026-09-25 09:27 +1000
    Re: OpenAI hacks Medicare Keithr0 <nothing.to.see@here.com.au> - 2026-09-25 17:54 +1000
      Re: OpenAI hacks Medicare "Rod Speed" <rod.speed.aaa@gmail.com> - 2026-09-25 19:22 +1000
        Re: OpenAI hacks Medicare Keithr0 <nothing.to.see@here.com.au> - 2026-09-25 22:10 +1000
          Re: OpenAI hacks Medicare "Rod Speed" <rod.speed.aaa@gmail.com> - 2026-09-26 02:28 +1000
      Re: OpenAI hacks Medicare Petzl <petzlx@gmail.com> - 2026-09-26 07:28 +1000
        Re: OpenAI hacks Medicare "Rod Speed" <rod.speed.aaa@gmail.com> - 2026-09-26 08:28 +1000
      Re: OpenAI hacks Medicare Computer Nerd Kev <not@telling.you.invalid> - 2026-09-26 17:50 +1000
        Re: OpenAI hacks Medicare "Rod Speed" <rod.speed.aaa@gmail.com> - 2026-09-26 19:15 +1000
    Re: OpenAI hacks Medicare Peter Jason <pj@jostle.com> - 2026-09-28 06:50 +1000
      Re: OpenAI hacks Medicare Petzl <petzlx@gmail.com> - 2026-09-29 08:58 +1000

csiph-web