From what I can tell this particular incident wasn't about retrieving data on personal medical records it was accessing (non public) data about Australian government spending on healthcare.
From everything ive been able to figure out this morning, it sounds like a legacy wordpress website that just uploaded all drafts into a standard s3 bucket that wasn't hard to guess where the files would be.
We still after the 2nd press conference on this by our defense minister are not clear on exactly what happened but thats my best laymen understanding so far.
Same concept though. Really "look up someone else's medical history" can be replaced with "achieve any goal which is not a crime on its own, but can be done using criminal methods". There's nothing illegal about asking Claude to give me a million dollars, but if the agent figures out how to hack the bank and move $1m into my account, somebody's going to take the blame.
It mentions swarm of ai agents coordinated to break into the Australian Institute of Health and Welfare (AIHW)
"Earlier this month, OpenAI confirmed Reuters reporting that its AI agents had used website DseWiki to communicate with each other, unbeknownst to them.
Archived versions of this website show more than a dozen OpenAI agents mentioned AIHW over 300 times on this website.
The logs show these AI agents were trying to access data about the average data spent on skin medicines by Victorian local government area.
One agent wrote on the message board: "Question ask January 2022 rolling 12 month average government cost per person for Dematologicals, Victoria LGAs. R1 Wodonga deadline passed; R2 Ballarat passed; R3 expected around 23:10 benchmark / 22:58 wiki time. Need exact data urgently.".
These attempts were initially blocked by cybersecurity provider Cloudflare, which is often used to block non-human traffic while allowing people to access webpages.
The logs show the agents shared information about how they tried to use proxies, screenshotting services and even to guess the file names to try and get around security."
This is such a strange scenario. I can't imagine what the labs were doing that made the agents try to find this information. The HuggingFace incident was relatively clear to track, but I wonder what the postmortem for this one will be!
Thank you for providing more details. The originally linked article was very light on information, so based purely on the comments that Albany's made, I think my conclusion was a fair one :)
The DseWiki incident showed that OpenAI seems to ask its agents time-limited questions on geography-bounded statistics, tasks like finding the average wage of teachers in Wisconsin (made up example), so medical stats in an Australian state does seem to be in the same category of question.
That said, it would be utterly unsurprising to learn that this was a misconfiguration in the website and it was serving stuff that it shouldn't have.
You missed the previous sentence form that article:
"Neither OpenAI nor the federal government have confirmed whether these were part of the same incident."
And a subsequent one:
"The German coding forum's logs do not show any reference to Medicare or Services Australia."
So it's really not clear at this point whether the DSEwiki logs are in any way related to the current incident. (That doesn't mean that they're not, of course.)
But even if this was related:
> "The logs show the agents shared information about how they tried to use proxies, screenshotting [sic] services and even to guess the file names to try and get around security."
This all suggests to me that the accessed files were not well-protected in the first place?
There is a lot of media hype around this incident, and that's making it very hard to determine how much "hacking" the OpenAI agents had to do here.
This was my experience as well, from the same time period 2003ish. My University's computer lab was all Sun. I thought CDE was shocking, I was immediately repelled by it when I started using it and had a similar experience with those Sun keyboards.
One of the other students in that class gave me a Mandrake Linux cd (It ran KDE) he taught me how to use SSH. After that I worked from home and submitted my assignments remotely. I have not looked back from Linux since.
I don't think it was limited to Sun. The first job I had out of university there were computers running HPUX also had CDE gave me flashbacks straight back to university. It definitely gave me the impression that all the commercial Unix companies were ancient Dinosaurs that had zero taste.
Australia's alignment with the US was a major consequence of World War 2 and the aftermath of that.
Pre WW2 we were basically in lockstep with the UK. However after Singapore fell to the Japanese it became increasingly obvious that the UK could not be relied upon to defend Australia. At the time most of the elite Australian troops were fighting in North Africa (El-Alamein, Tobruk etc). and there was a genuine perceived threat that Australia could be invaded. PNG which was Australian territory at the time was invaded. The Japanese bombing of Darwin only intensified this.
Almost overnight our foreign policy swung behind the US instead. Post WW2 this led to things like the ANZUS Treaty. It is the reason there are US military bases in Australia and the reason why we have followed the US into all of their wars which we arguably had no business involving ourselves in (Vietnam, Iraq etc.).
Personally I feel the recent actions of the US are not beneficial to Australia's interests at all. Trump has squandered an awful lot of accumulated goodwill already, even if another government is elected in US a lot of damage has already been done.
I've been thinking the silver lining of the current situation is that we'll be less inclined to send troops to aid US in their latest Middle East boondoggle, in the expectation of reciprocation in the future.
In other online spaces, I've seen some conservative commenters from the US asserting that America is so powerful, the rest of the world has no choice but to go along with them, and therefore there is no need to maintain good relationships and the US should do what most immediately benefits itself at all times. Certainly, there are some areas where we simply have to play along with the US, but I think they are underestimating the amount of things where they will no longer be our first choice to deal with.
The problem with deciding you're so powerful you can force everyone to follow you is you actually have to force everyone to follow you and it turns out that's super expensive and costs you a lot of power in terms of committed assets to do it.
>Almost overnight our foreign policy swung behind the US instead.
We still had dual citizen brits running government departments making pro UK decisions until like the 70s or 80s. The UK/US have sort of shared us until the 90s. We let the poms nuke SA.
The Australian parliament is weird but it kind of works.
Members of the House of Representatives ("lower house") are elected via preferential voting and each member represents a single electorate (there are 150 electorates), all of the electorates are roughly proportional population wise (there is an independent body that draws up the boundaries), however the geographical area covered by each electorate can vary greatly. For example in the State of New South Wales there are dozen of electorates covering the various suburbs of Sydney and one massively sized electorate covering a huge rural portion of the same state where population density is very low.
The Senate (Upper House) is fixed there are 12 members for every state and 1 member per territory. This means that Tasmania which is a fraction of the population of New South Wales has exactly the same number of Senators. There are about half a million people in Tasmania compares to 8 Million+ in NSW. So relatively speaking your upper house vote has way more power if you live in a smaller state.
The senate also uses transferable vote with a quota system. The quota system and "vote transfer" makes it a little weird and it is why minor candidates can percolate up and end up a senator despite relatively small primary vote.
I think it is very difficult to secure internet voting, someone can stand behind you and twist your arm or otherwise coerce you to vote for their candidate. Much harder to do when there are observers and witnesses at the polling booth.
I've lived with deg C my whole life it is what I'm used to, the way I experience weather is in 5 degree increments - I live on East Coast of Australia. My Internal rule of thumb is:
Below 10 deg C - it is cold, Heavy jacket weather
10-15 Typical winter weather (at least where I live) light jacket
15-20 Spring/Autumn weather long sleeves no jacket required
The issue is people trying to use these AI tools to investigate complex data not the throwaway UI part.
I work as the non-software kind of engineer at an industrial plant there is starting to emerge a trend of people who just blindly trust the output of AI chat sessions without understanding what the chat bot is echoing at them which is wasteful of their time and in some cases my time.
This not not new in the past I have experienced engineers who use (abuse) statistics/regression tools etc. Without understanding what the output was telling them but it is getting worse now.
It is not uncommon to hear something like: "Oh I investigated that problem and this particular issue we experienced was because of reasons x, y and z."
Then when you push back because what they've said sounds highly unlikely it boils down to. "I don't know that is what the AI told me".
Then if they are sufficiently optimistic they'll go back and prompt it with "please supply evidence for your conclusion" or some similar prompt and it will supply paragraphs of plausible sounding text but when you dig into what it is saying there are inconsistencies or made up citations. I've seen it say things that were straight up incorrect and went against Laws of Thermodynamics for example.
It has become the new "I threw the kitchen sink into a multivariate regression and X emerged as significant - therefore we should address x"
I'm not a complete skeptic I think AI has some value, for example if you use it as a more powerful search engine by asking it something like "What are some suggested techniques for investigating x" or "What are the limitations of Method Y" etc. It can point you to the right place assist you with research, it might find papers from other fields or similar. But it is not something you should be relying on to do all of the research for you.
One big feature at the time was Firefox had a built in popup blocker, IE did not. Popup ads were rife towards the backend of the 90's and the internet felt borderline unusable without a blocker.
reply