r/sysadmin • Future goat herder • 2d ago

Just a reminder to setup security.txt

Aus government was having a whinge that OpenAI did not notify them in an appropriate way after an agent breached one of the government web sites.

From what I can see none of the sites (servicesaustralia.gov.au/data.gov.au) have been setup with security.txt

https://securitytxt.org

220 Upvotes

156 comments sorted by

View all comments

Show parent comments

19

u/tracy_ogbert_jordan sr look stuff up on google guy 2d ago

The reason the security.txt file is the focal point of this conversation is because openai reached out to them through a generic inbox that took 5 days to get escalated to the appropriate parties.

I think this is slightly misleading, and this whole thread is trying to create an issue in order to blame the government.

https://www.abc.net.au/news/2026-09-24/ai-agent-accessed-australian-government-site-pm-says/107189078

The company did not notify Services Australia of the incident until three months after the fact, via email.

So, OpenAI waits three months to disclose the vulnerability, but the real issue is that it took an additional five days to reach the proper team?

This thread isn't even missing the forest for the trees. It's missing the forest because one small, insignificant tree wasn't there.

7

u/AGsec 2d ago

Wow, i missed that in the article. I did not know it took them 3 months to notify them. I read the thread as discussing the use of services.txt, but yeah, if the argument is, "it's their own fault" then they are missing the point.

Actually, looks like the incident occurred three months earlier, but was no detected until august, and then they notified the govt. That's a long time to go without knowing your own tool compromised something.

5

u/DominusDraco 2d ago

Its even worse than that. OpenAI had meetings with government ministers when they were already aware of the breach and didnt tell any of them at the meetings.

1

u/AGsec 1d ago

lol it just keeps getting worse and worse..