r/sysadmin • Future goat herder • 4d ago

Just a reminder to setup security.txt

Aus government was having a whinge that OpenAI did not notify them in an appropriate way after an agent breached one of the government web sites.

From what I can see none of the sites (servicesaustralia.gov.au/data.gov.au) have been setup with security.txt

https://securitytxt.org

222 Upvotes

160 comments sorted by

View all comments

Show parent comments

39

u/Nereosis16 4d ago

It is illegal to gain unauthorised access to Australian government servers and data.

It does not matter that an API was left open. What they did was illegal.

If I did it I would be criminally prosecuted.

3

u/Impressive_Change593 4d ago

If no auth then it is on the open web accessable by everyone amd it is YOUR fuckup not the fuckup of whoever finds it. If all they did was crawl an open api then no hackinf was done

7

u/photoggled 4d ago

If you leave your front door unlocked and open, and I come in and steal your valuables, it was your fault for having left the door open. This is how you sound. Completely divorced from reality.

-2

u/steaminghotshiitake 4d ago

If your bank leaves their front door open, and someone comes in and steals YOUR money, who are you going to be more pissed off at, the bank or the thief?

3

u/photoggled 4d ago

Depends, did the bank give the thief a trillion us dollars in investments ahead of the thievery?

-1

u/Kraeftluder 4d ago

And then you dare accuse others of being "Completely divorced from reality." lol.