Comment by BeetleB
18 hours ago
What's notable is:
1. AFAICT, they don't state whether the flaw has been fixed.
2. He said: "The government will establish a task force led by the Department of the Prime Minister and Cabinet to urgently examine the incident and determine whether existing processes are adequate for responding to AI-related cyber incidents."
First, I don't know how sophisticated the attack was, but it's interesting that he's positioning this as an "AI-related cyber incident". For all we know, their security was not up to snuff, and human hackers had already accessed the material.
At least OpenAI informed them of their poor security!
How do you protect against an arsonist lighting a forest on fire? The number one method is by setting up your property to be fire safe.
Really the days of being able to cast blame on the hacker, or even expecting anything to be done about it are over. Threat actors with AI have an absolutely massive amount of leverage in attacking and any weaknesses you have in your systems security posture and will be relentlessly exploited in incredibly short periods of time allowing horizontal and vertical exploitation. You will be ruined in mere moments, while punishment for the hacker may be years or decades away, if ever.
I have now seen several people using the “arsonist / forest fire” analogy in the context of the Australian hack, seemingly unaware that Australia does not treat arson and wildfires as acts of god that just happen and you only have yourself to blame for improperly preparing for it, but rather as acts of man that are addressed with things like “total fire ban” (if translated back to the AI context this would ban even individuals using airgapped local models), “levy fines” (e.g. 2M for a 20B corp so if translated back to OpenAI’s context ~1B), and “class action lawsuits” (e.g. 500M for a 10B corp so if translated back to OpenAI’s context ~50B).
Most AU fires are caused by lightning strikes.
Anyway, separate the OAI hack from the billions of hacks that are going to occur over the next few years by AI driven agents. The time for insecure systems is over.
As an Australian, I'd rather them spend the time and money fixing their insecure web sites than establishing a 'task force'. Because I can't see much useful stuff coming from herding a bunch of monkeys into a room and letting them just screech at each other, as monkeys do.
blaming the victim
Added to the fact that, if I recall correctly, according to US law it's a breach even if the data is publicly available but unintentionally.
Refer: Weev AT&T
Which is mad, really.
7 replies →
Not yet, as they haven't given details out. If they were not following standard security practices, then absolutely.
The government is not the victim, the public are. The government is responsible for protecting the public from attackers. Asking the government to do their job is not blaming the victim.
And when the victim doesn't do reasonable actions to safeguard, yes, they are also partially responsible.
If I hooked up a whole server infrastructure, made it possible to remote in to anything as root, no firewalls, no WAF, and security was an afterthought, I would still be responsible for bad actions not becoming with standard and acceptable security.
Even if the hackers shouldnt be hacking, I still did it wrong. I'm still partially responsible.