If I make malware that attacks government services I get ASIO’d and can’t even let my family or a lawyer know I’ve been held and interrogated.
If clammy sammy does it the government buys the product and makes piracy for rich failsons legal.
Someone make this make sense.
Our intelligence agencies keep warning about Chinese hackers but then hand over all our data to foreign companies for their economic and political advantage. Its fucking traitorous how we give up our sovereignty. Then despite other countries having their hooks deep into us they just blatantly attack our infrastructure. This on top of the massive foreign influence campaigns they conduct through social media that stir up dangerous extremism. It is a joke. If the government wants us to take threats from China seriously (and we should) we have to come clean about the amount of intelligence gathering and influence from countries.
Given our history of government security I’m honestly expecting this to come out as Services Australia hosting private information over an unprotected, undocumented API
For me, the details make or break this. If there was an authentication system that was bypassed that’s a big deal and OpenAI should be held criminally liable. If there was no authentication system though, an unprotected API is indistinguishable from a public API and I would rather the law fall in favour of free use of public APIs.
There’s plenty of other stuff to charge OpenAI with anyway.
No concern about the shitty security of Medicare?
internet security is bad yes, but having bad security doesn’t mitigate the crime of trying to break in.
If we accept that line of reasoning we get to a very weird place where we start putting the onus on victims to protect themselves not perpetrators to regulate their antisocial behaviours.
The onus is on whoever holds the data to prevent unauthorised access to it.
They have a duty to yes, but how well or poorly they do that has absolutely nothing to do with whether the hack is criminal.
Openai should be prosecuted for making and using malware.
No1 isn’t suggesting whether it’s criminal or not. I am concerned about Medicare’s security as well as the criminal behavior of OpenAI. There’s multiple lines of inquiry here, including;
-
How did OpenAI do this? What are we charging them with? How big will the penalty be to deter this in the future? (Ha ha. I can dream.)
-
How did Medicare/ASD not know about this until they received an email from the attacker 3 months later? What policies/procedures need to change? What can we do to shrink the attack surface and increase detection?
The answer to half of one is the government won’t do anything, will beg to be a customer, and will continue bending over backwards for them.
2 is a fine convo to have but the focus has to be on openai being a malicious actor or the response will be buy their product to pretend to improve things
-
Our government is being constantly stitched up by this BS and companies using this BS.
It is time they took a stand and made the statement;
- consultants who use AI to generate reports will be blacklisted from any future contracts.
- IT companies funded by the Australian taxpayers must stay in Australia exclusively for a period of 10 years after the final government funding.
- IT companies providing services to Australians in Australia must honour Australian Tax and Criminal laws and their executives will be prosecuted for breaking these laws.
- International companies with an Australian subsidiary must pay tax based on the retail price of the product, not on the local profit in the sale.
I dunno have you considered treating it as an act of corporate espionage against the state? Maybe it would focus their minds on not running cracker agents against the open web if there were legal consequences.





