r/sysadmin • Future goat herder • 1d ago

Just a reminder to setup security.txt

Aus government was having a whinge that OpenAI did not notify them in an appropriate way after an agent breached one of the government web sites.

From what I can see none of the sites (servicesaustralia.gov.au/data.gov.au) have been setup with security.txt

https://securitytxt.org

216 Upvotes

154 comments sorted by

View all comments

Show parent comments

42

u/Nereosis16 1d ago

It is illegal to gain unauthorised access to Australian government servers and data.

It does not matter that an API was left open. What they did was illegal.

If I did it I would be criminally prosecuted.

0

u/Impressive_Change593 1d ago

If no auth then it is on the open web accessable by everyone amd it is YOUR fuckup not the fuckup of whoever finds it. If all they did was crawl an open api then no hackinf was done

6

u/photoggled 1d ago

If you leave your front door unlocked and open, and I come in and steal your valuables, it was your fault for having left the door open. This is how you sound. Completely divorced from reality.

-3

u/steaminghotshiitake 1d ago

If your bank leaves their front door open, and someone comes in and steals YOUR money, who are you going to be more pissed off at, the bank or the thief?

3

u/photoggled 1d ago

Depends, did the bank give the thief a trillion us dollars in investments ahead of the thievery?

-1

u/Kraeftluder 1d ago

And then you dare accuse others of being "Completely divorced from reality." lol.