OpenAI apologies for Australia's Medicare Statistics hack
Transcript
But now let's get more on OpenAI's apology for hacking Australia's Medicare Statistics System in June with me in the studio is our national AI technology reporter, Cameron Wilson. Hi there, Cam. So what more did we learn about this hack? Yeah, so in a uh quite a contrite sounding blog post put out today called How We Will Do Better for Australia. Um, OpenAI put out an unsigned message talking about um what had happened in the incident, giving us some more details, and then talking about what it was going to do next to, in their words, try and re-establish trust in Australia. Um, and so in that we got some bit more information about um how the hack occurred, what it affected, and um how they also dealt with it in the aftermath. Was anything really new in there that surprised you? So there were a couple of things that stood out to me. The first thing was that we got a bit more knowledge about exactly um what the OpenAI agents had done to that Medicare Statistics web portal, which is run by Services Australia. People might remember that there were actually four different government websites accessed by the agents, but the government said, you know, the the three of them were not such a big deal, accessed relatively in the way that a normal person would do it, a real person, I guess you'd say. Um, whereas the Services Australia Medicare Statistics portal, we knew that these AI agents had gone further than just looking at it normally, but had done something that the government had called a hack. And we got some more details on that, which included saying that it had written to the servers, technical mumbo jumbo, but essentially what that means is like you know, it's a difference between going and looking at someone's door and you know poking your head in versus like actually trying to like stick a key in there and get in, and in this case, actually getting into non-public files. They also did other things like um try and find credentials, so that's the kind of login. So that's like you know, looking around the house, trying to find some spare keys anywhere, um, and that kind of thing. So that was quite, I think, notable in the kind of context of this because we'd heard that this government website did not have great security, but what we've heard now from OpenAI shows that it was not just purely a poorly secured government website, but some real kind of offensive, cyber attempt offensive moves by the AI agent. The other thing that I just noticed just before I came on air was that OpenAI said that it said that what was responsible for this hack was an internal model that did not have its normal cyber safety safeguards on it. So they said, you know, this is not one that we would release publicly, it would go further than what we you know than that. We knew that they had those models because that kind of model was responsible for that big um hack that we heard about a few months ago, that open AI hugging face incident where it actually hacked into another company, which was quite severe, um, a much bigger deal than what this one was in terms of actually what happened. But in this blog post, by attributing um this hack to that, they also said that the task that it was given was getting some medical data. It was told out, go and look at the internet, get up some research on specifically the spending on skin medicine in Victoria, some very specific stuff. But putting those two together, that's actually something new. They have said, according to this blog post, that they had taken a model that they knew didn't have its normal safety measures and intentionally let it go out and access the internet. That's beyond what we knew from the OpenAI hugging incident, uh hugging face incidents because we were told it broke out of an enclosure. In this blog post, I believe it actually says that they've got this model that wasn't given its normal safety measures, and then they said go on onto the internet. And I think that's a kind of like an important revelation in this. So open AI sounded contrite to you, said, but what are they promising to do? So they've announced a couple of things that they've said that one, we're working with government departments and those affected. Um we are uh uh wetting Australian government organizations, so businesses and governments take part in, they've got this, I think like $1.4 billion fund for kind of free access to open AI to bolster cybersecurity, you know, to turn the AI on your own systems to find vulnerabilities. Um and they also said they're gonna establish a Australian task force. So I think a group of experts who are gonna help advise it and also the Australian government on how to avoid something like this in the future. Thanks, Cam. Thank you.