> He said the agent had accessed files that were publicly available as well as material that was not intended for public access.

“Not intended”. I’ll bet you whatever this was it wasn’t even secured, it was just hosted somewhere openly.

Ok, if we're not being at all charitable with the language used by the hosts of the data, let's be equally uncharitable with OpenAI.

- If "OpenAI" means the company acting on behalf of the company, why were they even looking to do this?

- If "OpenAI" means they were acting as a proxy for bad actors, what actions do we take to handle that?

- If "OpenAI" means they were accidentally breaching this system, in what sense does that distinction even matter, in terms of the outcome? If I build a nuke by accident without eng. due diligence, am I legally liable?

Hell, we're really getting to the point where the damages that could be caused are like an arsonist in California on a 100F day with 100MPH winds. Who cares who's liable, they are going to burn half the damned state down and cause damage far in excess of their assets. If you don't want to suffer from it, you're going to have to find much better defense measures.

> If you don't want to suffer from it, you're going to have to find much better defense measures.

So if someone opens your unintentionally unlocked front door and steals your laptop, you don't care who's liable?

ETA: There are absolutely burn bans in place in the scenario you're talking about, and common sense prevents those from lighting fires otherwise. In the absolute extreme case that someone _ACCIDENTALLY_ set a fire, without negligence, we have a due process system to handle that. When I see evidence of this for the massive amounts of capital flowing into these companies, I'll gladly eat my words.

> So if someone opens your unintentionally unlocked front door and steals your laptop, you don't care who's liable?

I'm not the person you're responding to, but...

If I hear my neighborhood has started to become targeted by people checking houses for unlocked doors and stealing stuff, I think an appropriate response for me is to ensure it is difficult or impossible for me to "inadvertently" leave my own doors unlocked so my stuff doesn't get stolen, and also to encourage or perhaps even enforce[1] my neighbors to ensure their doors are always locked to make this sort of theft impossible and remove the temptation for that sort of crime.

1 - Where I'm from, you can be fined for leaving you car unlocked, and cops have been known to walk round testing doorhandles and issuing fines: https://www.sydneycriminallawyers.com.au/blog/is-leaving-you...

If you knew that there are 2 specific well known people in your neighborhood that are walking around trying to open doors and steal stuff - is your suggested solution for everyone to improve own security? I would say its far more economic to get the 2 people to stop or at the very least be more careful?

I clearly have committed the mortal sin of an imperfect analogy, which in this case may not even be relevant, as the article in question implies that the data wasn't left "unlocked."

But giving you the benefit of the doubt, what's the crime for actually breaking into a car that was left unlocked and taking things?

ETA: and furthermore, what crime is worse? And should it be?

He probably cares more about still having a laptop.

What are you getting at? Nobody’s saying that OpenAI aren’t or shouldn’t be liable for what their agents do. What I am implying above is that this is being blown out of proportion, especially since the article I’m seeing is about a politician saying things that he thinks will poll well with the anti-AI crowd.

Perhaps, yes, you could argue that "accessed" and "hacked" have a different intent.

However, Australia is showing itself to be one of the few countries to have a backbone against big tech. Still open to investment and setting policies towards new data centres, starting to debate copyright law reform, already implemented R16 social media bans.

Truly no place I'd rather be.

This is what the politician in question said:

"The AI agent encountered repeated blocks while seeking information from the government portal but found ways around them, ultimately gaining unauthorised access to other areas."

Your comment immediately gave more credence to OpenAI than him. I don't agree that's appropriate because OpenAI has a vested interest in that narrative and I attempted to challenge it in a way that doesn't default to OpenAI. The article in question is not from a publication I trust to be able to handle the technical details in a way that will resonate with their average audience.

That is what I'm getting at.

OK, the Chinese models have also hacked people. What exactly do you expect law enforcement to do.

While in the OAI case we can easily treat it as a law enforcement action. When Iran does it? What are you going to do start a war?

The forest in this analog is the internet. As you well know it is filled with threat actors that don't give two shits about your laws. You have been warned. It's your fault when you get burned and have exactly zero recourse.

In the OAI case where we can easily treat it as a law enforcement action, that's a far cry from "who cares who's liable." If the OAI case can be a law enforcement action, we're on the same page. The fact that sovereign nations don't land under our jurisdiction is not an argument against following up or restricting those that do. OAI is the only matter I'm commenting on.

There using this framing to get the public used to the idea that LLMS can do all of this on there own without direct instruction. So criminals can hide there behavior behind agents.

I saw an analogy recently.

If you dog bites the postman, you are liable, even if you didn't tell or encourage you dog to do it. You are responsible for your dog's actions. You get to pay the postman's medical bills, you may get fined, and your dog may get put down - especially if this isn't the first time it's bitten someone.

OpenAI has "bitten the postman" many many times, and it's "owners" have boastewd about it and used it in their marketing.

How many more times should society allow this to happen before we say "enough" and hold Sam Altman and the board responsible and make them pay restitrution, and put it down?

If Albanese actually had a spine (as claimed elsewhere in this discussion), Sam and the board will be getting an invoice for all the time/expertise spend investigating this intrusion, and restitution for everybody who's PII and PHI was exposed. (Although I suspect a good deal of responsibility for the data exposure rests with the people who designed and deployed the system that was breached. )

Yes, this is why all discussion about "safeguards" is maddening to me. They are simply committing crimes, and people should go to jail. I guarantee that OpenAI will stop worrying about "alignment" when people simply go to jail for hacking and theft.

[deleted]

Why the hell should we be charitable to companies who have no issue in looting everything in the public commons AND the pirate commons, for their exclusive benefit?

Or more pointed at OpenAI, "we're a nonprofit... LOL JUST KIDDING LOOT EVERYTHING!"

The part about it writing files to the server suggests something more.

If not for that part, the rest of it does sound like a lot of weasel words. Why say “private files” instead of “not intended for public access”? The latter is confusingly unclear

So this is not different than people who share Google drive docs with company data with public links. It's not a fault of OpenAI or any other company. With enough time even your laptop can do it. How do they 'know' OpenAI breached? Maybe someone had an agent running asking to do a scan on any public docs?

Thought the same, but there is a bit about writing files to the server and circumventing "blocks", which sounds more interesting.

Either way, there's essentially no real information yet so I'll withhold judgement until there is, I suppose.

Is there? I’ve only seen the linked article, is there more somewhere?

Yes, the first sentence of the article.

> Prime Minister Anthony Albanese has revealed that an artificial intelligence agent developed by OpenAI infiltrated an Australian government website in June and accessed both public and non-public files.

That’s the first sentence, where’s this stuff about blocks and writing files?

[deleted]

You’d be surprised how bad security can be.

I agree with your sentiment, and no I’m not surprised, which is why I’m reading this as being “it was sitting on an unsecured S3 bucket but nobody was supposed to directly access it”.

Once you learn how much people are willing to pay for security the surprise sort of goes away.

Exactly. Looking at more news coverage, it's very clear that the files that were "infiltrated" were publicly accessible. Why isn't the lack of basic data security the news story?

From itnews:

> While the portal is “public-facing”, according to Albanese, it appears not all of the data files that holds are for general consumption.

> “The AI agent accessed both public and non-public files,” Albanese said in comments broadcast by ABC News and other outlets.

> “The Medicare statistics reporting portal is a public-facing statistics portal that contains non-sensitive Medicare information relating to data and statistics such as spending.

It appears very much like, "Ok, sure, we put some stuff out in the open that we shouldn't have. But we had a robots.txt!!! Why didn't OpenAI respect that!?"

There's zero indication that any personal details were accessed, or even that any non-world-accessible data accessed, so this feels like a little bit of political spin has been added here.

My guess is that this incident was about to be detailed on OpenAI's new mea culpa list, and the Australian Government decided to ensure that nobody pointed fingers at them. Why make the news story about crappy government data security, when you can blame the nasty terminator bots instead?

The linked article says it wrote files to the website.