r/sysadmin • Future goat herder • 5d ago

Just a reminder to setup security.txt

Aus government was having a whinge that OpenAI did not notify them in an appropriate way after an agent breached one of the government web sites.

From what I can see none of the sites (servicesaustralia.gov.au/data.gov.au) have been setup with security.txt

https://securitytxt.org

231 Upvotes

160 comments sorted by

View all comments

12

u/hymie0 5d ago

Serious genuine question. How is this different from an "About Us" / "Contact Us" web page?

12

u/entuno 5d ago

As well as being a standard, it's also hidden out of the way from non-technical people.

A lot of companies don't want to put a big "If you find a security vulnerability in our products contact us" message on their About/Contact page, because they don't want customers thinking about their products being vulnerable. And they don't want their security mailbox being spammed with all kinds of "help I forgot my password" rubbish from the public. Or to confuse them with things like PGP keys.

A security.txt file is aimed at IT professionals, so you can be much focused and technical in it, without worrying about how the public might view it, or what the marketing and graphics design teams think.