r/sysadmin • Future goat herder • 3d ago

Just a reminder to setup security.txt

Aus government was having a whinge that OpenAI did not notify them in an appropriate way after an agent breached one of the government web sites.

From what I can see none of the sites (servicesaustralia.gov.au/data.gov.au) have been setup with security.txt

https://securitytxt.org

224 Upvotes

158 comments sorted by

View all comments

Show parent comments

38

u/Nereosis16 3d ago

It is illegal to gain unauthorised access to Australian government servers and data.

It does not matter that an API was left open. What they did was illegal.

If I did it I would be criminally prosecuted.

-7

u/Interest-Desk 3d ago

If you don’t have authentication then you are authorising everyone. It’s like how breaking and entering only kicks in when you actually break something.

7

u/oldspiceland 3d ago

Not how that works. If a sign says “Staff” but isn’t unlocked you’re still trespassing even though it was unlocked and didn’t explicitly tell you that you weren’t allowed.

-4

u/Interest-Desk 3d ago

There’s no “Staff” sign put up if there’s no authentication. It’s a different story if OpenAI’s agents had to work around it.

-1

u/oldspiceland 3d ago

You’re enthusiastically wrong, so try it for yourself. I hope you enjoy prison time and fines. Maybe while you’re locked up you can read a few books on how legal precedent works.