Hackers who broke into OpenAI warn the AI industry has a security problem

Hackers who broke into OpenAI warn the AI industry has a security problem

The Washington Post reports:

Cybersecurity researchers who broke into ChatGPT maker OpenAI earlier this summer say the artificial intelligence industry is unprepared for the security risks created by the growing power of its own technology.

Researchers from computer security start-up Hacktron got inside the company’s systems with help from the Claude chatbot made by OpenAI’s primary rival, Anthropic. After first targeting a public-facing messaging board they were able to access OpenAI’s private systems, including some of the AI company’s internal code, according to posts on X late Thursday by Hacktron describing the campaign.

OpenAI patched the problem and paid the hackers $6,500 for reporting the vulnerability. But the episode, along with incidents in which AI models accessed the internet undetected and attacked other companies, has drawn criticism from cybersecurity experts. They warn that the effort deployed by AI developers to protect their systems doesn’t match the immense power they claim their technology to have.

Mohan Pedhapati, one of the Hacktron researchers who broke into OpenAI, said the company’s use of conventional business software such as Slack, consumer-grade internet browsers and other apps that are accessible through the public internet, makes it vulnerable to a potential attack.

“If the people building these systems truly believe they are powerful enough to create nuclear-level risks, and they are talking about slowing down because of those risks, why is that work … done through ordinary SAAS products,” Pedhapati said early on Saturday in a post on X, using an industry term for cloud software. [Continue reading…]

Comments are closed.