Maybe I'm missing something here. Do I read it correctly that OpenAI failed to implement "defense in depth" and that a properly configured firewall would have likely contained this?