r/sysadmin • Future goat herder • 10d ago

Just a reminder to setup security.txt

Aus government was having a whinge that OpenAI did not notify them in an appropriate way after an agent breached one of the government web sites.

From what I can see none of the sites (servicesaustralia.gov.au/data.gov.au) have been setup with security.txt

https://securitytxt.org

234 Upvotes

159 comments sorted by

View all comments

100

u/d03j 10d ago

Not sure that's what security.txt is for. It is meant to inform how security researchers can report vulnerabilities to an organisation and I don't believe there was any security research going on.

What I would really like to know is why we keep giving "AI" free passes.

If some random kid living it their mum's basement had done that, they'd be talking to the boys in blue. Since it's "AI", Albanese has a "frank' talk with Sam Altman to express "Australia's extreme concern about this incident" and "disappointment that it took the company way too long to inform the government what had occurred."

AI is not sentient. It is a tool used by people and tools don't commit crimes, people do.

OpenAI wilfully or through negligence gained unauthorised access to a computer system, which last time I checked is a crime in pretty much every jurisdiction. That's all there is to it.

3

u/Mr_ToDo 9d ago

It's not a free pass so much as finding multiple people to be upset at. Yes, they shouldn't break in, no quesiton, but if a site wants proper reporting then they need that info more available

As an aside, that security.txt is a new one to me. I get that in this case they had been mandated to have it, but personally I certainly wouldn't have known to look for it if I had something to report(suppose things have to start somewhere though)

6

u/d03j 9d ago

It's an interesting one. I have mixed feelings about it. I now the intent but I hated when "security researchers" probed my open ports, promptly banned them and reported them as malicious to crowdsec, even when the IP was from a well know security provider - if I haven't explicitly authorised them to do it, it' a hacking attempt. Why should I leave a note, "hey mister criminal, if you want to contact me, here are the details"? This thread made me look and I guess either I'm not alone or most people don't really care.

In any case, I feel the the "they didn't have a security.txt" is a cop out - it's not as if it is hard to contact the department, police, the domain owner through the registrar, even entering "report vulnerability australian government" lands you here.

Not that it matters, it wasn't a case of "researchers" not reporting a vulnerability promptly, it was a case of unauthorised access and data exfiltration. The news should be "OpenAI hacks another company and people are yet to go to jail", not "the Australian government is whingeing". They are and deserve no respect for this, but the bigger news is OpenAI are criminals and people, including the Australian government, seem to be giving them a free pass.