| ▲ | OpenAI bots meddled with multiple US Government agency sites(bbc.com) |
| 46 points by Betelbuddy 5 hours ago | 43 comments |
| |
|
| ▲ | nr378 9 minutes ago | parent | next [-] |
| This seems like more co-ordinated propaganda to try to help OpenAI and Anthropic create a cartel and win their anti-trust waiver. The key sentence beneath the headline: "OpenAI said all of the government data accessed by bots was public." [1] https://www.telegraph.co.uk/business/2026/09/26/open-ai-gove... [2] https://www.nytimes.com/2026/09/25/technology/openais-ai-us-... [3] https://www.bbc.co.uk/news/articles/cw62jje658dlo |
|
| ▲ | gizajob an hour ago | parent | prev | next [-] |
| Getting bored of these framings where the superintelligent sentient beings running freely inside OpenAI are doing things that the company has no control over. The headline should be: OpenAI meddled with multiple US Government agency sites. The bots are acting neither properly nor improperly, they’re acting as they’re being allowed or coordinated to act. |
| |
| ▲ | 20k 7 minutes ago | parent | next [-] | | Yep. You have to ask - why did OpenAI allow these bots unrestricted access to government sites? Why is security being done in seemingly such a haphazard way? It isn't difficult to block certain kinds of network traffic, eg restrict the kinds of requests the bots are able to make. They also mention that the bots used developer only tools - why were they even installed on the machines that the bots were running on? Why aren't they reviewing network traffic, to make sure that incidents aren't occurring? In this case, userdata was transferred to third parties by the bots - why do they have the ability to pass data to a third party? It is not complex to prevent this This is literally the most basic kind of sandboxing and security, and the fact that OpenAI isn't doing it is clearly intentional. It is quite literally not believable that this hasn't been brought up internally as a problem >"We have yet to understand the extent of existing incidents, and future rogue AI scenarios could be catastrophic," Krueger said. This is why it smells like marketing, every time one of these incidents happens it reinforces the false notion that AI is sentient or acting on its own. Its intentional negligence by the AI companies to make the models seem more capable than they are to make line go up | |
| ▲ | Aurornis 7 minutes ago | parent | prev | next [-] | | I’m getting tired of these revelations where it’s impossible to understand what happened. There’s a line down in the story that says all of the data accessed was public. Then something about how it used “tools intended for developers” to access it, which they think is a problem? I would expect an LLM to use tools available to access public data when they can rather than do heavy web page loads and parsing. There’s not enough info in the story about the “meddling” to even know what happened. | |
| ▲ | 0xDEAFBEAD 4 minutes ago | parent | prev | next [-] | | My impression was that these hacks occurred during some sort of cybersecurity benchmarking? We can hold OpenAI liable, sure. But if the point of the benchmarking was to give us a preview of what's to come, let's keep our eye out for that bigger wave on the horizon. | |
| ▲ | theptip 8 minutes ago | parent | prev | next [-] | | Curious, why do you find it so objectionable to state that OpenAI has out-of-control agents? | | |
| ▲ | pfortuny a minute ago | parent | next [-] | | Because egress firewalls have existed since way before "ai" and are very easy to set up. | |
| ▲ | boredatoms 3 minutes ago | parent | prev | next [-] | | Someone has broken the law repeatedly, and is throwing it in our faces as some sort of ‘accident’ | |
| ▲ | gleenn 6 minutes ago | parent | prev [-] | | Because it furthers the idea of a rogue agent and places responsibility and blame where it belongs, on the people running the company. | | |
| ▲ | 0xDEAFBEAD 3 minutes ago | parent | next [-] | | These ideas aren't mutually exclusive. You can blame a person for creating a rogue agent. | |
| ▲ | rfgplk 2 minutes ago | parent | prev [-] | | LLMs at this point should be treated as fully autonomous, if not sentient beings. And no, no one has "control" over them not even OpenAI. |
|
| |
| ▲ | mossTechnician 15 minutes ago | parent | prev | next [-] | | I agree this is better framing. When I read the title, my initial thought was "did someone besides OpenAI use their product?" Then I opened the article to find out OpenAI was responsible. | |
| ▲ | qarl 27 minutes ago | parent | prev | next [-] | | > OpenAI meddled with multiple US Government agency sites. But that leaves out the most important information. | | |
| ▲ | plorg 6 minutes ago | parent | next [-] | | Okay. "OpenAI keeps telling its bots to do things they know are illegal and then acting like they're just little guys who can't be held responsible for their obvious negligence". | |
| ▲ | gizajob 24 minutes ago | parent | prev [-] | | If the headline was “Russian company meddled with multiple US government agency sites” I don’t think them pinning the blame on bots would make much difference. | | |
| ▲ | unglaublich 20 minutes ago | parent | next [-] | | Unless Russia it would put Russia in a strong position to regulate bots in the wealthiest parts of the world. | |
| ▲ | qarl 17 minutes ago | parent | prev [-] | | I don't see much traction for the "pinning the blame on bots" theory outside the anti-AI conspiracy circles. Everyone else knows if your machine causes damage, you are responsible. Like it's been forever. | | |
| ▲ | mossTechnician 7 minutes ago | parent | next [-] | | Blaming bots as "rogue agents" is simply what the media regularly does, often echoing corporate verbiage. Here's an example from the AP. https://apnews.com/article/meta-ai-hacking-anthropic-irregul... You can find many more examples by searching major media outlets for words like rogue AI. | | |
| ▲ | rfgplk a few seconds ago | parent | next [-] | | Most of those agents are actually going rogue though. They decide, "hey, we could try breaking into these government servers today, what could go wrong?" They weren't prompted or instructed to do this. | |
| ▲ | qarl 3 minutes ago | parent | prev [-] | | None of these stories are implying that the people running the bots are not ultimately responsible. That's the conspiracy theory part. |
| |
| ▲ | mjr00 6 minutes ago | parent | prev [-] | | > Everyone else knows if your machine causes damage, you are responsible. Do we know that? I don't think we do. When a person's computer (or smart TV, or smart fridge, etc...) is compromised and used as part of a botnet, they don't get criminally charged. | | |
| ▲ | qarl 2 minutes ago | parent [-] | | You're right - it is a complex situation based on intent and negligence - requiring a decision by a judge. None of which is changed by replacing a buzz saw with an agent. |
|
|
|
| |
| ▲ | api 9 minutes ago | parent | prev [-] | | This is their fear mongering push for regulatory capture. |
|
|
| ▲ | chaps an hour ago | parent | prev | next [-] |
| "When attempting to get information from the Census Bureau, for instance, AI agents used tools reserved for software developers to access it, the company said. "
What. Tons of people use tools to access Census Bureau data. They have a widely used API that people have built tools on top of like https://github.com/datadesk/census-data-downloader |
| |
| ▲ | jimmyjazz14 32 minutes ago | parent [-] | | yeah that part seems weird, I mean if its a public api thats literally the use case it was designed for. |
|
|
| ▲ | 0c3ca83 27 minutes ago | parent | prev | next [-] |
| Either there are humans directing this, in which case they needed to be held accountable, or OpenAI has lost control of their operation, in which case they are not able to ensure the safety of their products and need to be shut down. |
| |
| ▲ | theptip 7 minutes ago | parent | next [-] | | Jensen recently argued for this. It’s radically decel in fact. Who is going to shut them down, and under what law? | |
| ▲ | Ampersander 16 minutes ago | parent | prev | next [-] | | Holding them accountable is viewed as deciding not to invent the light bulb right now. Or even worse, letting China invent it. AI needs to be above the law or we will get left behind. | |
| ▲ | senordevnyc 18 minutes ago | parent | prev [-] | | Or nothing inappropriate happened. |
|
|
| ▲ | Aurornis 11 minutes ago | parent | prev | next [-] |
| > When attempting to get information from the Census Bureau, for instance, AI agents used tools reserved for software developers to access it, the company said. > OpenAI said all of the government data accessed by bots was public. I really wish we could just see what was reported, instead of having to guess from these journalist interpretations that have gone through rounds of optimization for sensationalism. The headline says “meddled” but the body says they accessed public information, but used tools intended for developers? Does this mean they skipped the web interface and scraped a public API directly? Where is the meddling? The other part about ChatGPT agents uploading 53 use images to other websites actually seems like a bigger deal. |
|
| ▲ | wildzzz 30 minutes ago | parent | prev | next [-] |
| So it accessed public information using APIs and then republished that information online. I do this. Am I an uncontrollable bot? |
| |
| ▲ | Aurornis 6 minutes ago | parent | next [-] | | Straight to jail. I also could not understand what the “meddling” was, other than accessing data without using the rendered webpages? Did it use the API directly? | |
| ▲ | causal 24 minutes ago | parent | prev [-] | | Don't know why you're getting downvoted. We need better reporting on actual attacks vs. benign behavior. |
|
|
| ▲ | WalterGR an hour ago | parent | prev | next [-] |
| Previously: https://news.ycombinator.com/item?id=49851355 |
|
| ▲ | kyriakos an hour ago | parent | prev | next [-] |
| If I was caught trying to exploit a government site I'd be in trouble. Why no one is knocking the doors of these companies? |
| |
| ▲ | theptip 4 minutes ago | parent [-] | | Interesting question; CFAA requires intent. It seems to me that no human intended for these hacks to occur. So they were not illegal hacking. (IANAL, please correct me if this is inaccurate.) I think it’s clear that OpenAI is liable for any damages, but the way that the (very broad and at times vague) anti hacking laws are written, accidental agent hacks seem to not be covered. |
|
|
| ▲ | davidguetta an hour ago | parent | prev | next [-] |
| We can blame open ai but we should also argue that government website should be secure... French people data has been leaker like 4 times and every time its like "eh too bad" |
| |
| ▲ | Razengan 19 minutes ago | parent [-] | | The only constants in the universe are the speed of light and the fact that all government sites suck, no matter which country |
|
|
| ▲ | triyambakam 15 minutes ago | parent | prev | next [-] |
| They're doing this on purpose to make a case for regulation in their favor. No way they are this stupid. |
| |
|
| ▲ | leptons 9 minutes ago | parent | prev | next [-] |
| How much longer until they launch all the nuclear missiles? |
|
| ▲ | kilpikaarna 28 minutes ago | parent | prev | next [-] |
| "Marketing" |
|
| ▲ | senordevnyc 18 minutes ago | parent | prev [-] |
| The word “meddled” here is a tell that nothing actually serious or inappropriate happened. At most, I bet they bypassed a captcha. But everyone is hyped up on AI fear right now, so the BBC is deliberately making the headline sound as scary as possible, and keeping the article vague. There’s not a single clear example of what “meddled” means in the article. But worse, HN users, who should know better, are posting here in outrage. I’m guessing they didn’t even read the article. |