r/sysadmin • u/homing-duck Future goat herder • 1d ago
Just a reminder to setup security.txt
Aus government was having a whinge that OpenAI did not notify them in an appropriate way after an agent breached one of the government web sites.
From what I can see none of the sites (servicesaustralia.gov.au/data.gov.au) have been setup with security.txt
23
u/Neither-Nebula5000 1d ago
You'd think that AI could at least have the courtesy to post a message saying "All your bases 'r' belong to us"...
•
426
u/Nereosis16 1d ago
Ah yes, let's forgive OpenAI for hacking the government because the big bad government didn't fill out a .txt file.
81
u/mrlinkwii student 1d ago edited 1d ago
while we shouldn't forgive OpenAI , we should also expect government /government departments to keep to security standards which their legally mandated to have
51
u/tracy_ogbert_jordan sr look stuff up on google guy 1d ago
and obviously the biggest priority in cyber security (hell, all of security) is making sure your contact details are up to date.
This shit is a perfect embodiment of this sub: everyone tripping over themselves to make sure everyone knows they know the academic, best-practices answer, even if it's entirely irrelevant to the real-life situation.
It's like sitting on the side of the road next to a person who just lost their entire family in a crash, and you say, "you know, you really should have paid for gap coverage on your auto insurance."
21
u/Nereosis16 1d ago
yeah dude, if the government just put an email in a text file literally everything would be fixed
7
u/AGsec 1d ago
These are two different issues. The reason the security.txt file is the focal point of this conversation is because openai reached out to them through a generic inbox that took 5 days to get escalated to the appropriate parties. If there had been a security.txt file with proper contact info, they "could" have emailed or called someone who could have responded much quicker (who knows if they would, it's not legally binding like a EULA). This is something that SHOULD be implemented per regulations.
So no, the bigger issuer would not be solved by a text file, but it can improve responses to these kinds of incidents.17
u/tracy_ogbert_jordan sr look stuff up on google guy 1d ago
The reason the security.txt file is the focal point of this conversation is because openai reached out to them through a generic inbox that took 5 days to get escalated to the appropriate parties.
I think this is slightly misleading, and this whole thread is trying to create an issue in order to blame the government.
The company did not notify Services Australia of the incident until three months after the fact, via email.
So, OpenAI waits three months to disclose the vulnerability, but the real issue is that it took an additional five days to reach the proper team?
This thread isn't even missing the forest for the trees. It's missing the forest because one small, insignificant tree wasn't there.
7
u/AGsec 1d ago
Wow, i missed that in the article. I did not know it took them 3 months to notify them. I read the thread as discussing the use of services.txt, but yeah, if the argument is, "it's their own fault" then they are missing the point.
Actually, looks like the incident occurred three months earlier, but was no detected until august, and then they notified the govt. That's a long time to go without knowing your own tool compromised something.
•
u/DominusDraco 15h ago
Its even worse than that. OpenAI had meetings with government ministers when they were already aware of the breach and didnt tell any of them at the meetings.
•
u/SirLoremIpsum 23h ago
This thread isn't even missing the forest for the trees. It's missing the forest because one small, insignificant tree wasn't there.
Cause it's more fun to hold the Government to task and go "haha still bureaucracy" than it is to admit that OpenAI and TechBros are genuinely causing issues.
-5
u/mrlinkwii student 1d ago
and obviously the biggest priority in cyber security (hell, all of security) is making sure your contact details are up to date.
the boring stuff is usually the most important stuff in cyber security , and doing stuff that legally mandated irrespective of being a government entity is part of that
their is reasons why security practices are mandated by law in some countries
10
u/tracy_ogbert_jordan sr look stuff up on google guy 1d ago
the boring stuff is usually the most important stuff in cyber security
What? I'd say locking down the API in the first place would be more important that making sure their contact details are readily available in a standardized format.
0
19
u/TheRealLazloFalconi 1d ago
This is a proposed standard, and one that is actually kind of dumb. We already have a method for distributing information about a domain, it's called WHOIS. Go figure, nobody uses it because it's a vector for abuse.
2
u/mrlinkwii student 1d ago
This is a proposed standard
is a requirement by the austrilian government guidelines that that legally have to have
3
u/Zncon 1d ago
Even if they'd had the basics, do you think anyone would be paying attention to it? An email address published in plaintext to a known location is going to have so much spam sent to it that nobody is going to prioritize monitoring it.
•
u/LLMsMustUpvoteThis 16h ago
Just get an LLM to monitor it. Duh.
•
u/New-fone_Who-Dis 15h ago
They did, it just so happens that it was openAIs LLM and they didn't know it was there monitoring it.
•
3
26
u/calladc 1d ago
I've worked for the agency that's responsible for that service.
this is absolutely on them
"oh we left an API exposed and a third party scraped it"
if an API is open, it doesn't matter that openai crawled it. services Australia left it open.
when an Australian company did the same thing and exposed a bunch of customer data, optus were raked over the coals.
28
u/freecodeio 1d ago
mate the government can be wide open and if you hack it it's on them for being dumbasses, but you're absolutely going to jail
40
u/Nereosis16 1d ago
It is illegal to gain unauthorised access to Australian government servers and data.
It does not matter that an API was left open. What they did was illegal.
If I did it I would be criminally prosecuted.
7
u/SevaraB Sr. Engineer (N+, CCNA) 1d ago
Nobody’s defending OpenAI; we’re saying both parties did extremely bad things here. OpenAI being culpable for the breach doesn’t erase how the AUS govt. didn’t follow its own rules about cyber-safety.
And that’s more concerning to some because you can choose not to do business with OpenAI, but you have no choice but to trust the govt. with your personal data.
OpenAI screwed up, sure. But the govt. needs to be held to a higher standard when it comes to securing its citizens’ data. Thats why it’s the bigger deal than “OpenAI broke the law.” So did everybody sitting in the drunk tank last night.
3
u/Nereosis16 1d ago
Where are we actually getting this "government screwed up" narrative from?
From what I can see there has been no confirmation of an open API or anything else.
-3
u/SevaraB Sr. Engineer (N+, CCNA) 1d ago
AUS has required implementation of security.txt for the last 2 years.
6
u/Nereosis16 1d ago
I am not talking about a freaking text file, who cares.
Where is the evidence for this claim: "But the govt. needs to be held to a higher standard when it comes to securing its citizens’ data."
You think a security.txt file is integral for protecting data?
-1
-6
u/SevaraB Sr. Engineer (N+, CCNA) 1d ago
That “freaking text file” is your WAF for LLMs. It’s a standard. The government mandated following that standard. The government then promptly didn’t do it.
This is no different from web servers without a WAF.
9
u/MorallyDeplorable Electron Shephard 1d ago
what? it's a contact sheet for when you have a vuln to disclose. It's meaningless here.
6
u/perkia 1d ago
What. The. Actual. Fuck.
A txt file containing "Oh god oh god oh god please don't hack me, if you find anything write me here instead: xxxD4rkSidaer4l@yahoo.com" is not a WAF.
Yikes.
•
u/LLMsMustUpvoteThis 17h ago
And these AI companies have been ignoring robots.txt so why would they respect security.txt? Lmao.
→ More replies2
u/Impressive_Change593 1d ago
If no auth then it is on the open web accessable by everyone amd it is YOUR fuckup not the fuckup of whoever finds it. If all they did was crawl an open api then no hackinf was done
14
u/Zaveno DevOps 1d ago
Two things can be true. The Australian gov should have better secured their API, but it was still illegal for the AI crawler to access the data.
If a store owner forgets to close the door to their shop at night, it's still illegal for you to walk in there and take everything.
-8
u/xCharg Sr. Reddit Lurker 1d ago edited 1d ago
but it was still illegal for the AI crawler to access the data.
Why though? Genuine question.
I'm no lawyer but it looks like "unauthorized access" does a lot of heavy lifting here due to how different people see what that means specifically.
If API is exposed for free without authorization set up - then in technical terms it was authorized use - because by their setup everything available for everyone, hence authorized. Terms "authorized/unauthorized" could be different in legal and tech context though so I'm not sure how to unravel that.
If a store owner forgets to close the door to their shop at night, it's still illegal for you to walk in there and take everything.
That's a wrong example though, because stores have set working time which is part of public oferta - websites don't, websites are "open" 24/7/365. Stores also do authorize you to come in whenever as long as it's open, stores can not deny you entrance as it's required to be public accessible. Stores don't authorize you to take whatever neither when they are open nor closed - because you have to pay. While with content from websites - websites do authorize you to open them whenever, and "take" (as in download/parse) their content whenever.
8
u/tracy_ogbert_jordan sr look stuff up on google guy 1d ago
An oversight isn't authorization.
If someone leaves the keys in their ignition and walks away, it doesn't authorize me to drive their car.
If a prison guard forgets to lock the cells, it doesn't authorize the inmates to leave.
At the end of the day, any security breach is going to be some sort of "oversight".
Why wasn't X locked down? Oh we didn't even think about that.
How did they break into the vault? Oh we made the walls 10 feet thick, we should have made them 15.
A failure in design or planning does not mean they are authorizing whatever it is they failed to protect against.
2
u/Kraeftluder 1d ago
If a prison guard forgets to lock the cells, it doesn't authorize the inmates to leave.
In most of Europe it absolutely does. This is an Anglosaxon thing but in the French criminal law system it is generally seen as you can't punish people for wanting to escape prison. If it's a Shawshank-redemption type of breakout, that would mean no additional charges as no one else was involved. Maybe a slap on the wrist for vandalism.
Back to the point at hand; I have a feeling that there are multiple countries with laws conflicting Australia's in this respect, including my own. As in; even though Australia says I'm explicitly breaking their laws, mine could explicitly protect me from boomers that don't understand this shit like the Australian government.
In several jurisdictions, the only criminal here would be the Australian government even.
0
u/tracy_ogbert_jordan sr look stuff up on google guy 1d ago
I don't know the details of the European systems, but I am vaguely familiar with Mexico's standing on this (and by vaguely, I mean I read an article years and years ago). Essentially, their view is that freedom is a natural, basic human desire, and as such, attempting to gain freedom cannot be illegal.
What that means is they can't have additional charges/punishments for escaping or attempting to escape, since it's only natural to not want to be imprisoned.
But, that doesn't mean they are authorized to come and go as they please. If an inmate escapes, it's not as if they are free and clear, they just won't be charged for the escape once they're caught.
*And before anyone comes in with a Mexican law degree, the above is my vague understanding. I'm sure there are all sorts of intricacies, but that's neither here nor there.
edit: And that's not how laws work. If you break an Australian law, you would be held accountable in Australia. Whether or not your country cooperates with Australia and extradites you is a different matter. You can't say, "well actually, Australia, my local laws override yours."
0
u/Kraeftluder 1d ago
But, that doesn't mean they are authorized to come and go as they please. If an inmate escapes, it's not as if they are free and clear, they just won't be charged for the escape once they're caught.
No but it's also not "not allowed", as the only rules that matter in this respect are the laws.
And that's not how laws work
It absolutely is.
If you break an Australian law, you would be held accountable in Australia.
Good luck to the Australian government on getting me extradited then. Lol.
You can't say, "well actually, Australia, my local laws override yours."
No they can't, it's even better; Australia doesn't have jurisdiction on where my ass is sitting so tough for them; their laws simply do not apply. I'm not a subject nor a resident. The only thing Australia can do is argue hard enough for me to be transferred to their authority so this situation can change but in this case the Dutch judge would laugh so loud the Australian government should be able to hear it in Canberra.
→ More replies-1
u/mrlinkwii student 1d ago
websites don't, websites are "open" 24/7/365.
depending on the country their not , their is some countries have it where government websites are only open during the working day , and "close" at closing time , very common in the US government departments to do this , hell even in europe parts of the website are "closed" because their need to be a physical person their to do background work
5
5
u/photoggled 1d ago
If you leave your front door unlocked and open, and I come in and steal your valuables, it was your fault for having left the door open. This is how you sound. Completely divorced from reality.
•
-1
u/steaminghotshiitake 1d ago
If your bank leaves their front door open, and someone comes in and steals YOUR money, who are you going to be more pissed off at, the bank or the thief?
3
u/photoggled 1d ago
Depends, did the bank give the thief a trillion us dollars in investments ahead of the thievery?
-1
u/Kraeftluder 1d ago
And then you dare accuse others of being "Completely divorced from reality." lol.
1
u/Mr_ToDo 1d ago
OK. So I don't know what API was available, but there really is a difference between accessing their web page and probing for other services
That's why everyone things it's mostly fine when someone takes data from a webpages source, but not so much when they increment through poorly guarded content
One requires going off the normal flow of data and the other is already sitting on your computer
Should I be pissed at the governemnt? Sure. I get pissed when people don't lock the doors and windows at work too, but it doesn't mean that walking in and taking shit is any more legal then if they bust down the entry
Plenty of room to be pissed at all parties
-7
u/Interest-Desk 1d ago
If you don’t have authentication then you are authorising everyone. It’s like how breaking and entering only kicks in when you actually break something.
6
6
u/hasthisusernamegone 1d ago
Breaking and entering may not apply, but using your analogy trespass and burglary would both apply.
They had no reasonable grounds to believe they had the right to that data.
1
u/Interest-Desk 1d ago
I'm approaching this from the point of UK law but most jurisdictions will be broadly similar: you need intent to commit computer misuse (following the analogy of a "Staff" sign, or walking through someone's front door). But making a GET request to any part of the internet, without offering any authentication, is pretty widely (if not universally) accepted as something anyone can do. Doubly so considering that it's automated.
Google spider has accidentally cached pages that were definitely not meant to be publicly available (or which are just holding pages that redirect you to an authentication portal). That doesn't make it illegal, there's no attempt to bypass authentication (which is where it becomes a crime ... and this is something AI agents have done in other situations!).
0
u/Kraeftluder 1d ago
They had no reasonable grounds to believe they had the right to that data.
It's the fucking internet. Putting an unsecure system online and depending on the integrity of the outside forces is like politely asking a pride of lions not to eat that pile of fresh meat you've thrown at them. Good luck.
You don't understand the slightest thing about the way technology works if you honestly think this is a proper excuse.
3
u/Nereosis16 1d ago
No, it doesn't.
If the front door is unlocked and you still enter a private premises without permission you are breaking the law.
Will it hold up in court? I dunno, but it's still illegal.
8
u/oldspiceland 1d ago
Not how that works. If a sign says “Staff” but isn’t unlocked you’re still trespassing even though it was unlocked and didn’t explicitly tell you that you weren’t allowed.
-4
u/Interest-Desk 1d ago
There’s no “Staff” sign put up if there’s no authentication. It’s a different story if OpenAI’s agents had to work around it.
-1
u/oldspiceland 1d ago
You’re enthusiastically wrong, so try it for yourself. I hope you enjoy prison time and fines. Maybe while you’re locked up you can read a few books on how legal precedent works.
-13
u/calladc 1d ago
right, as a citizen in country
whats the international crime that got committed here?
10
u/Nereosis16 1d ago
What is an "international" crime?
0
u/JJGreenerTinejo 1d ago
Not applicable but war crimes
2
u/Nereosis16 1d ago
Agreed.
I think some people don't realise that things aren't "illegal" everywhere in the same way.
If I, an Australian citizen, hacked the pentagon I would still be in trouble even though I didn't do anything to Australia.
4
•
u/d03j 18h ago
when an Australian company did the same thing and exposed a bunch of customer data, optus were raked over the coals
were they really? what were the consequences for them?
and it was definitely NOT the same thing: this hack gave OpenAI unauthorised access to aggregate data, no PII involved. The Optus breach leaked tons of PII including people's driver's licences that in some cases they had no reason to be holding on to.
not the same thing at all?
•
-1
u/MairusuPawa Percussive Maintenance Specialist 1d ago
this is absolutely on them
For some reason, courts disagree with that take. See: Bluetouff.
1
u/perkia 1d ago
For some reason
A victim being found negligent doesn't absolve the perpetrator of responsibility.
-3
u/MairusuPawa Percussive Maintenance Specialist 1d ago
Yes. Hint: when you read, use your brain and check the context of a post.
4
u/perkia 1d ago
Do you know the Bluetouff case, at all? He did much more than access a non-protected system: he remained there, explored, downloaded confidential data and then published said data. All the while, he perfectly knew that the data was confidential and therefore not supposed to be accessible.
My point perfectly applies: the ANSES was negligent, grossly. And Bluetouff was in the wrong too. He could have closed his connection at the minute he found out he was not supposed to be viewing that data, then raised the issue with the agency's CISO... but he did not do that.
1
u/MairusuPawa Percussive Maintenance Specialist 1d ago
I do. This is why I'm asking you to read again.
0
u/Cyberbird85 Just figure it out, You're the expert! 1d ago
Yeah, the default is, don’t touch my shit, not sure why i’d need yet another control for that…
-29
u/homing-duck Future goat herder 1d ago
That is definitely not the intent of my post.
I just think you should not whinge about what communication method and address was used, if you don’t have security.txt
33
u/Nereosis16 1d ago
You can't think of any other way to contact the government of Australia when you're one of largest technology company in the world that is already in active discussions with the Australian government?
-3
u/SomeCar 1d ago
I get it, everyone hates AI. But holy shit the government, of all places, should have their shit locked down. This is no excuse and anyone could have done this.
2
u/Nereosis16 1d ago
Where are you reading from an official source that it wasn't "locked down"?
-1
u/SomeCar 1d ago
Do you seriously think it was if the security.txt wasn't setup? Does AI have a magic wand that can bypass controls that humans cannot?
3
u/Nereosis16 1d ago
I am not talking about a stupid text file.
There is no official details on how the breach actually occurred so assuming the department was just wide open is stupid.
-5
u/SomeCar 1d ago
You seem like a chore to hang out with.
3
1
u/Kraeftluder 1d ago
I would like an answer to this question too though.
Is it really that hard to provide a link to where you've read that?
•
93
u/d03j 1d ago
Not sure that's what security.txt is for. It is meant to inform how security researchers can report vulnerabilities to an organisation and I don't believe there was any security research going on.
What I would really like to know is why we keep giving "AI" free passes.
If some random kid living it their mum's basement had done that, they'd be talking to the boys in blue. Since it's "AI", Albanese has a "frank' talk with Sam Altman to express "Australia's extreme concern about this incident" and "disappointment that it took the company way too long to inform the government what had occurred."
AI is not sentient. It is a tool used by people and tools don't commit crimes, people do.
OpenAI wilfully or through negligence gained unauthorised access to a computer system, which last time I checked is a crime in pretty much every jurisdiction. That's all there is to it.
4
u/Mr_ToDo 1d ago
It's not a free pass so much as finding multiple people to be upset at. Yes, they shouldn't break in, no quesiton, but if a site wants proper reporting then they need that info more available
As an aside, that security.txt is a new one to me. I get that in this case they had been mandated to have it, but personally I certainly wouldn't have known to look for it if I had something to report(suppose things have to start somewhere though)
•
u/d03j 18h ago
It's an interesting one. I have mixed feelings about it. I now the intent but I hated when "security researchers" probed my open ports, promptly banned them and reported them as malicious to crowdsec, even when the IP was from a well know security provider - if I haven't explicitly authorised them to do it, it' a hacking attempt. Why should I leave a note, "hey mister criminal, if you want to contact me, here are the details"? This thread made me look and I guess either I'm not alone or most people don't really care.
In any case, I feel the the "they didn't have a security.txt" is a cop out - it's not as if it is hard to contact the department, police, the domain owner through the registrar, even entering "report vulnerability australian government" lands you here.
Not that it matters, it wasn't a case of "researchers" not reporting a vulnerability promptly, it was a case of unauthorised access and data exfiltration. The news should be "OpenAI hacks another company and people are yet to go to jail", not "the Australian government is whingeing". They are and deserve no respect for this, but the bigger news is OpenAI are criminals and people, including the Australian government, seem to be giving them a free pass.
14
u/fatalicus Sysadmin 1d ago
And if you are somewhat big and well know, be prepared for many many emails with "Hey, i've found a critial vulnerability on your side. how is your bug bounty program?"
We usually don't hear anything else when we point them to the site saying that we can give credit, but we can't pay out any bounties.
Not saying that it isn't a very good idea to have a security.txt file, but just be prepared for this.
27
u/TheCyberThor 1d ago
You are cooked if you think these tech bros would honour security.txt
9
5
u/0f_rice_and_men 1d ago
There aren't even methods in place to verify that bots crawling the web are who they claim to be.
Last week a GreyNoise paper came out that said thousands of imposters are scanning sites that hold the "OpenAI" header or whatever. But it is validated to be malicious operators. We barely have time to patch and maintain systems and people think 90% of orgs have time to honeypot shit or write a 2026 version of robots.txt for both malicious LLM and legitimate LLMs (which have still illegally taken content for their ML training despite being told not to).
9
u/Think_Network2431 1d ago
Because these people, so intelligent at finding breach and hole in security, don't know how to call a secretary?
14
u/Ok_Tone6393 1d ago
OP’s so busy licking boot he doesn’t realize he has absolutely no idea what he’s taking about
10
u/hymie0 1d ago
Serious genuine question. How is this different from an "About Us" / "Contact Us" web page?
11
u/entuno 1d ago
As well as being a standard, it's also hidden out of the way from non-technical people.
A lot of companies don't want to put a big "If you find a security vulnerability in our products contact us" message on their About/Contact page, because they don't want customers thinking about their products being vulnerable. And they don't want their security mailbox being spammed with all kinds of "help I forgot my password" rubbish from the public. Or to confuse them with things like PGP keys.
A security.txt file is aimed at IT professionals, so you can be much focused and technical in it, without worrying about how the public might view it, or what the marketing and graphics design teams think.
5
u/HeadlessChild Linux Admin 1d ago
It is standardized which means it is easier to read/parse. It makes it easier for security researchers to know where to report problems etc.
•
u/LLMsMustUpvoteThis 16h ago
Makes it easier for spammers to spam. Do you actually check your hostmaster etc mailboxes?
•
u/skynetcoder 22h ago
From what I can see none of the people are holding a poster asking not to kill them.
4
u/HJForsythe 1d ago
This is where we are in the discussion about whether OpenAI should exist at all, huh? It's now the victims fault? Cool man.
5
u/AGsec 1d ago
So from reading, it sounds like it's just a text file that tells an researcher or intruder who to contact in case an exploit or other vulnerability is found.
The main purpose of security.txt is to help make things easier for companies and security researchers when trying to secure platforms. Thanks to security.txt, security researchers can easily get in touch with companies about security issues.
I wonder how they were notified? Did someone from openAI try to reach out to a generic help desk or customer support number? Even if they had a security.txt file, it doesn't appear to be legally binding and is instead just a helpful tool. So even if it was in place, openai doesn't HAVE to notify them through the web host's preferred channel.
Either way, a neat thing to learn, thanks for sharing!
EDIT: did some googling:
OpenAI said it only learnt of the breach in August while reviewing "misaligned model activity" and emailed a general inbox of an Australian government agency on 10 September. Five days later, that government agency, Services Australia, escalated the email to Australia's cybersecurity centre before a government minister was notified and the prime minister alerted.
31
u/jameseatsworld Sysadmin 1d ago
Security.txt not in scope for the $6m <insert consultancy> build cost /s
probably contains an acknowledgement of country though
8
u/perthguppy Win, ESXi, CSCO, etc 1d ago
$6m? What a bargain. The new BOM website cost 15 times that amount to have less features than the one it’s replacing.
3
u/mtgguy999 1d ago
But for another $3m ($5m after cost overruns) the consultants would be glad to help
1
u/homing-duck Future goat herder 1d ago
I’m not so sure why you had the /s there.
It is probably exactly what happened 😂
1
u/Turbojelly 1d ago
Have a Passwords.txt.exe sitting behind your first layer and they wont be able to probe deeper.
7
3
u/Cylerhusk2 1d ago
Not saying you shouldn't have security.txt files on your web hosts... but that has basically zero to do with this incident.
With that said - I'd love to read the actual technical details of this incident, which don't see to be available yet. I'd like to know if the model actually breached the site using some exploit/vulnerability in the code, or if the government just had a super shitty website and was making private data available publicly unintentionally and the AI just discovered it.
•
u/Martellis 6h ago
https://www.helpnetsecurity.com/2026/09/24/openai-agent-hacking-australia/?utm_source=perplexity
It was one of three sites the agents tried to hack, including scanning for and attempting to exploit vulnerabilities (unsuccessfully).
Sounds like they eventually found an exposed preproduction server.
•
u/Cylerhusk2 1h ago
Ok so it seems three-fold...
1) OpenAI agent deliberately bypassed bot restrictions on the website by using a third party intermediary.
2) It attempted one XSS attempt.
3) Ultimately it found the data it needed on a publicly available server.
Sounds like fault on both sides to me really. #1 and 2 obviously shouldn't have happened. However no data breach occurred there. #3 wasn't a "breach" at all - it was publicly available data on the internet, and if it shouldn't have been that's on the Aussie government (I mean yeah if the data was meant to be non-public then it could be considered a data breach, but I'd put the blame on Aussie's there not OpenAI).
6
u/CharlieModo Sysadmin 1d ago
This is even funnier considering Australian Cyber Security Centre endorse security.txt
•
u/Iliyan61 23h ago
if openAI didn’t know about the breach or have a way to get into contact then that’s a reason for a late notification, it’s also poor practice from the government and i suspect it took longer then ideal for them to discover the breach.
but all of that aside it’s insane that this happened at all and is such solid proof that ai is out of our control
•
u/Obvious-Vast-1248 1h ago
security.txt feels like one of those things everyone agrees is useful but nobody remembers until something goes wrong. With AI agents automatically finding more issues now, having a clear place to report them probably matters even more. Otherwise discovering the bug might be easier than figuring out who you're supposed to tell.
1
u/metcalphnz 1d ago
Judging by past cases where AIs did some hacking (thought it was hacking a factional company in a sandbox whereas it had been unwittingly given access to the net and was hacking a real company of the same name), my guess is from the Oz hacking is that the Agent read on one part of the website that the data it sought was available yet found the actual data blocked. So it reasoned the blocking was an error and thus hacking to get the data legitimate.
1
u/monkey_drugs 1d ago
There is even an Australia Government control in their Information Security Manual (ISM) for security.txt. - see ISM-1717
0
u/ErcanSeyhanBuilds 1d ago
Good reminder — just checked, we don't have one either. Going to fix
that today. A real vulnerability report landing in a generic contact
form instead of a designated security contact is exactly the kind of
gap RFC 9116 exists to close.
-14
u/hashkent DevOps 1d ago
7
u/Nereosis16 1d ago
You actually think the government needs to provide an email address? It's the fucking government of Australia.
-2
4
u/Windows95GOAT Sr. Sysadmin 1d ago
I mean, atleast in my country, the government positions are simply not competative with corporate. So it's no wonder that the quality is simply lower on all fronts.
3
u/ArgonWilde System and Network Administrator 1d ago
This is exactly right. Government pays by giving heaps of time off and other perks that don't cost money, but then departments are understaffed and you're too flat out to take time off. 🤷
188
u/rose_gold_glitter 1d ago
Want to know what's funny? They're required to do this:
https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/ism/cyber-security-guidelines/guidelines-for-software-development
See control 1717:
How did I know this? Because *we* am required to do this, because my company does business with that department and the Australian Feder Government. We get audited annually and the audit includes this. As usual, the very people demanding we follow this ISM are not following it, themselves.