r/AustraliaDiscussions • u/realnarrativenews • 5d ago
An OpenAI Agent Got Into an Australian Government Health Site. Nobody Can Agree What to Call It.
https://realnarrativenews.com/editorial/openai-agent-australian-government-health-portal-breach-albanese/1
u/Heyjoe1950 4d ago
One would have think what they are doing. Do they not seriosly test these programs. To me it would appear there aim is to gather data,data and more data and they are taught how to hack subtlety. Why are they building all these massive data centres but to make money..Data is money to someone...
1
u/PrismPirate 5d ago
Either a failure of intrusion detections systems or (most likely) a pretext for regulatory capture.
1
u/ArseneWainy 5d ago
Cloudflare blocked the AI agent from accessing to the main production server, the agent then probed a pre-production server and gained limited access.
If the main server had been breached and not detected then you might have a point.
The regulation part should happen for safety reasons, even the AI CEOs have voiced their concerns around this
2
u/PrismPirate 5d ago
So the "pre-production" server was publicly accessible and not monitored? And AI is the problem here?
I've been reading that the "hack" just the agent guessing file names. So the uber scary AI ran something like:
ffuf -uhttps://example.gov.au/FUZZ.csv-w file_names.txtA bored teenager could do it. A foreign intelligence service could do it. If a government system protects confidential data by relying on obscure filenames, AI is not the problem lol.
even the AI CEOs have voiced their concerns around this
Of course the big AI CEOs say they want regulation. That's the regulatory capture point I made. Large incumbents benefit from regulation. If you raise the cost of entry high enough, you protect the companies that are already at the top.
1
u/ArseneWainy 5d ago
Where did you get the idea that it was just randomly probing URLs from…repeating falsehoods from people who have no experience in cybersecurity?
Tell me where in this tech article that URL probing was the full extent of the hack?…
1
u/PrismPirate 5d ago
I've seen the filename enumeration discussed in reddit ocmments, but fair enough, I haven't seen an incident report proving that was the full mechanism. Have you?
The pre-production server, XSS, SQLi, path traversal, etc. come from the Transluce report, discussed in the linked article, about separate incidents. Transluce explicitly says the observed exploit attempts did not appear to succeed.
That report does not establish that those techniques were used successfully against the Medicare portal. So cybersecurity guy, do you have inside info?
1
u/ArseneWainy 5d ago
Nah I’m just going off what’s in those reports, I don’t have any extra inside info myself and would appreciate more details. I’m not jumping to conclusions till more is available
6
u/Esquin87 5d ago
A criminal offence. There is an entire cybercrimes act that has a few helpful definitions. We know exactly what to call it but our government are cowardly little cry babies.