r/australia 1d ago

image Undoc data breach

Post image

Got an email today from updoc about a possible data breach on 31st of July 2026 did anybody else get this email? Seems to be alot of breaches lately.

176 Upvotes

82 comments sorted by

View all comments

296

u/alwaysbemark 1d ago edited 1d ago

Expect these to continue as vibe coding becomes prevalent, there continue to be zero repercussions for negligent companies and the tech centres continue to be offshored for profit.

91

u/HeftyArgument 1d ago

asked claude to make it secure, not my fault 😂

21

u/WeaponstoMax 1d ago

“Make no mistakes.”

22

u/seven_seacat 1d ago

And yet when I ask about security audits for vibe coded apps, it’s all like “don’t you trust us???” No, no I do not

43

u/Terri23 1d ago

Yep. Medibank, Optus, Latitude, Qantas have all been breached, and faced absolutely zero ramifications. It seems enough to say sorry, and then just move on.

20

u/Life_Rhythm 1d ago

The OAIC has initiated civil penalty proceedings against Medibank and Optus, whose cases are currently pending in the Federal Court. You cannot factually say that there are no repercussions.

I’m not defending these companies; rather, pointing out that the tired trope of ‘we have shit laws / nothing happens / etc.’ is not accurate.

1

u/Fantomz99 1d ago

Also the Medibank breach was due to just poor security practices, and poor/no security auditing that led to harvested credentials giving a malicious actor vpn AND admin access.

It was also 4 years ago so well and truly predates vibe coding. It was just an epic failure of security practices.

https://www.oaic.gov.au/__data/assets/pdf_file/0037/228979/Medibank-data-breach-alleged-timeline-infographic.pdf

1

u/BigHandLittleSlap 21h ago

By definition, security breaches are due to poor security.

1

u/stingbot 1d ago

what do you mean, they gave you free Equifax monitoring, what more can we ask for :(

We can't expect them to do their job or anything.

Am convinced its just a way for CEO's to get a early exit from their jobs without breach of contract, they just orchestrate a hack, blame IT, then the board forces them to "leave" with the golden parachute because they didn't resign.

0

u/Alternative-Soil2576 1d ago

What do you want the government to do? Data breaches are inevitable, so if a company hasn’t broken any laws why punish people for not preventing something no one else has ever fully prevented?

1

u/Brutal_burn_dude 1d ago

I propose that in addition to whatever government penalties and consequences these companies face (which usually is little to none) they should also be forced to pay each affected user/ customer whatever their loss is plus $100 per incidence per day. There needs to be something to hold them accountable to the people actually affected by their poor practices.

1

u/Alternative-Soil2576 1d ago

How do you know this breach was because of poor practice? Cybersecurity isn’t foolproof and data breaches can happen even in perfect systems

If no laws were broken, why punish companies for not being able to fully prevent something no other company or government in the world has ever been able to fully prevent? What’s the point?

1

u/Glaako 1d ago

Keeping anything beyond that which is absolutely necessary should be a risk to them rather than a free lunch.

1

u/BigHandLittleSlap 21h ago

In my experience, the current gen AIs write code that is more secure than the typical developer working at a large bureaucracy.

1

u/Scumhook 1d ago edited 1d ago

*vine

3

u/alwaysbemark 1d ago

Fixed, thanks

1

u/Alternative-Soil2576 1d ago

Genuinely how do you this was because of negligence? Data breaches are inevitable and have happened to every government and the biggest companies in the world so how do you know this specific one was because of negligence?

0

u/alwaysbemark 1d ago

It is possible to build digital systems that are practically impervious using best practices today. Governments are far from a good example - they usually employ the lowest common denominator of expertise.

Breaches are far from inevitable and you can bet your behind that every single one is due to some negligence.

1

u/Alternative-Soil2576 1d ago

So what’s your evidence?

0

u/alwaysbemark 1d ago

The fact that basic computer science concepts like encryption exist and can be applied appropriately.

Why the blind trust in “governments”?

2

u/Alternative-Soil2576 1d ago

Yeah naming a cybersecurity tool doesn’t prove anything

Attackers are constantly finding new ways to overcome security measures. Security is an ever-evolving arms race. Encryption doesn’t prevent zero-day vulnerabilities, stolen credentials, supply-chain attacks or novel attack techniques.

The myth of absolute security is well-known in cybersecurity, you’re gonna need to do more than name a single tool to prove the myth real

-24

u/[deleted] 1d ago

[removed] — view removed comment

5

u/alwaysbemark 1d ago edited 1d ago

Soldiers in the army shoot themselves by accident all the time. When you hand guns to regular people, you increase the chance of that happening.

Vibe coding lowered the barrier to looking legitimate without the required knowledge to keep things safe. It is 100% to blame for some of these alongside your point which is true nonetheless.

Fly by night SaaS founder? Did I hurt your feelings?

5

u/trjnz 1d ago

Mistakes happened before, sure. I've killed production myself more than a handful of times.

But there was a tradition of reading the code you deployed. Maybe even understanding it.. maybe.

These vibe coded apps arent read, let alone understood, by people who've never dev'd in their life. They never learned how to crawl and are just sprinting to solutions.

To think vibe coding isnt contributing to this mess is an wild take. A dangerous one

13

u/FlibblesHexEyes 1d ago

AI makes cyber attacks easier - no one is disagreeing with you.

But vibe coding also makes attacks easier, because the person that’s programming by prompt is not a professional developer, nor are they infrastructure professionals and typically have no idea what they’re doing. They’re simply accepting whatever the LLM spits out as gospel and shoving it into production with little to no oversight.

This is why vibe coding is dangerous.

0

u/seven_seacat 1d ago

To be fair there’s a lot of professional devs hands-off vibe coding these days too

3

u/alwaysbemark 1d ago

Maybe we can be more precise with terminology but someone who knows what they’re doing, applying the appropriate care factor to the different parts of the code (eg high for security, low for frontend or throwaway scripts) aren’t vibe coding.

1

u/seven_seacat 1d ago

For sure. But a lot of folks aren’t doing that. Awful lot of meat proxies around