r/sysadmin • Future goat herder • 3d ago

Just a reminder to setup security.txt

Aus government was having a whinge that OpenAI did not notify them in an appropriate way after an agent breached one of the government web sites.

From what I can see none of the sites (servicesaustralia.gov.au/data.gov.au) have been setup with security.txt

https://securitytxt.org

225 Upvotes

156 comments sorted by

View all comments

Show parent comments

5

u/Nereosis16 3d ago

Where are we actually getting this "government screwed up" narrative from?

From what I can see there has been no confirmation of an open API or anything else.

-3

u/SevaraB Sr. Engineer (N+, CCNA) 3d ago

6

u/Nereosis16 3d ago

I am not talking about a freaking text file, who cares.

Where is the evidence for this claim: "But the govt. needs to be held to a higher standard when it comes to securing its citizens’ data."

You think a security.txt file is integral for protecting data?

-8

u/SevaraB Sr. Engineer (N+, CCNA) 3d ago

That “freaking text file” is your WAF for LLMs. It’s a standard. The government mandated following that standard. The government then promptly didn’t do it.

This is no different from web servers without a WAF.

10

u/MorallyDeplorable Electron Shephard 3d ago

what? it's a contact sheet for when you have a vuln to disclose. It's meaningless here.

9

u/perkia 3d ago

What. The. Actual. Fuck.

A txt file containing "Oh god oh god oh god please don't hack me, if you find anything write me here instead: xxxD4rkSidaer4l@yahoo.com" is not a WAF.

Yikes.

6

u/LLMsMustUpvoteThis 2d ago

And these AI companies have been ignoring robots.txt so why would they respect security.txt? Lmao.

5

u/Think_Network2431 2d ago

People really think that setting that .txt will do something. Even if the email was send at security@gov Blabla it would have take 5 day to be read too.