AI-generated password warning alert showing critical cybersecurity threat, password vulnerability, system risk, and data access breach visualization Latch
Look, I want to take an initial view on the widely reported “Hack” of Medicare by an OpenAI agent as revealed by Australian Prime Minister Anthony Albanese today. I think we need to look into this in more detail before jumping to the conclusion that all AI is destined to bring down society and hack our personal data.
EFTM Snapshot: An OpenAI agent found data Medicare left exposed, and the real lesson is that government IT security needs to lift its game, not that AI is coming for your health records.
Australians are – rightly – triggered by any report of a hack, especially given the Optus, Medibank and Latitude hacks over recent years. In each of those incidents actual hackers maliciously attempted to gain access to private systems and obtain personal and very private data from those businesses.
Today, we learned that an “OpenAI agent” in the process of researching medical funding in Australia was accessing a Medicare Statistics website, and in the process of doing so was able to gain access to information that was not public.
Now, that’s very, very different to hacking into Medicare’s servers and hacking the private data of Australians. It is, don’t get me wrong, still technically a “hack” – but it’s vastly different to what the “pub test” might see as being a hack.
As an example, and it’s a really silly one, the EFTM logo used here on this website is intended for your public viewing. Somewhere on our server sits a “Christmas” version of the EFTM logo, intended for use in December. Imagine we upload that to a location on our server, and it’s never linked to or shown on any page. If a hacker mucking around went digging and found that it was in fact stored in a directory on this server that was listed with public viewable access rights, then they could – theoretically – see that image.
In my reading of the statements made, this access could be that simple.
The Prime Minister is pissed. Saying “Today I spoke with the CEO of OpenAI, Sam Altman, to express Australia’s extreme concern about this incident,” the PM said.
“And I also expressed my disappointment that it took the company way too long to inform the government what had occurred.
“The nature of the way that the notification occurred as well was unacceptable.”
Open AI say “As we’ve shared publicly, OpenAI is conducting an extensive review of misaligned model activity during training and evaluation and notifying third parties when our review identifies potential impacts to their systems.
“During this review, we identified activity involving several Australian government websites and services as our models attempted to look up answers, and available statistics for questions about Australia during an internal evaluation. In the course of that, our models took actions we did not intend.
“Our review found no evidence of patient records being accessed. The information accessed included aggregate health statistics and internal file names. We notified the organisations and are providing technical information to support their investigations and help address potential security vulnerabilities. Our overall review is ongoing, and we remain committed to transparency about these issues and to sharing what we learn as that work continues.”
The most detail we got was from the Deputy PM Richard Marles who told the ABC “It (The Agent) sought information, information was not given, and then it effectively hacked into that medical portal and got that information anyway,” he said.
“And that’s the unauthorised access, which we are very concerned about.
“The information is benign in a sense and as I say, the impact is relatively minor, but the incident is very serious.”
Frankly, I think this “hack” is an important warning to Private and Government organisations about IT security. AI is smart, it’s as smart as the smartest hacker, in fact one AI agent could have the knowledge of all the smartest hackers.
The fact is, if you asked the best hackers (White Hat – the good ones) to access the same Medicare Statistics Reporting Service that this Open AI Agent accessed, I bet you my house that they would have found the same information.
What’s needed is less focus on the “AI Hack” and more focus on needing better, stronger security across all systems because if anyone’s going to find a way in, they’re going to do it with the help of AI.
And, at the same time as all the reporting and scaremongering today, it should be noted that we’ve never had a fundamental breach of any federal government database. Your ATO records and your health records have never been accessed. And yes, hackers are always trying.
Call me a sceptic, but all this also helps the Albanese Government gain public support for their AI regulation doesn’t it?
Trev is a Technology Commentator, Dad, Speaker and Rev Head.
He produces and hosts several popular podcasts, EFTM, Two Blokes Talking Tech, Two Blokes Talking Electric Cars, The Best Movies You’ve Never Seen, and the Private Feed. He is the resident tech expert for Triple M on radio across Australia, and is the resident Tech Expert on Channel 9’s Today Show and appears regularly on 9 News, A Current Affair and Sky News Early Edition.
Father of three, he is often found in his Man Cave.
Beats has unveiled its new flagship over-ear headphones, Beats 360, offering its first-ever customisable headphones…
Qualcomm has announced their next generation of processors, unveiling the Snapdragon 8 Elite Extreme Gen…
It’s been a busy few months for high-end consumer phones, with the latest addition to…
The NBA 2K franchise is one of the biggest sports game series in the world,…
Getting internet throughout your home without running cables everywhere is a hassle. Mesh internet systems…
Last night, Google unveiled the new Googlebook range, with devices from five different manufacturers starting…