Live data from Hacker News

Security.txt

securitytxt.org

11–20 of 148 posts

Re: Security.txt

#12

I seem to remember suggesting jobs.txt as a listing for a company’s open positions. Someone even made a site promoting the idea. What I mean to say is that the concept of a domain is much deeper than html, and we use it so shallowly. The web is distributed and simple if we want it back.

Can you expand more on this? What do you mean by “much deeper than html”?

Re: Security.txt

#13
post #10

Earlier quoted context omitted.

> If you're worried about spam, build in a bounce-back This is really bad advice. Always disable spam filtering outright on abuse@ and postmaster@, never filter them, never bounce anything . Read every one. I'm not saying hook those mailboxes up to automatically make a JIRA case on each inbound -- there is screening to be done. However, the idea of abuse@ is that spam is often forwarded directly to it if it's origina…

Reading all mail to postmaster@ has been utterly impractical for many years.

If you're one person with a vanity domain, maybe. If you're running a business that operates mail, it's mandatory.

Re: Security.txt

#16
post #10

Earlier quoted context omitted.

Reading all mail to postmaster@ has been utterly impractical for many years.

If you're one person with a vanity domain, maybe. If you're running a business that operates mail, it's mandatory.

abuse@: yes. postmaster@: no.

If people have trouble contacting a business by email, they don't try to use email to fix the problem.

They very sensibly go to the web site and try by phone or Twitter or some other medium that isn't the one that isn't working.

Re: Security.txt

#17
post #11

I think humans.txt ( http://humanstxt.org/ ) fits more, and already exists.

I've never heard of this. I wonder how many websites implement this. I tried a bunch of sites, but the only one I could find that had a humans.txt file was google:

Google is built by a large team of engineers, designers, researchers, robots, and others in many different sites across the globe. It is updated continuously, and built with more tools and technologies than we can shake a stick at. If you'd like to help us out, see google.com/careers.

Re: Security.txt

#18
post #16

Earlier quoted context omitted.

If you're one person with a vanity domain, maybe. If you're running a business that operates mail, it's mandatory.

abuse@: yes. postmaster@: no. If people have trouble contacting a business by email, they don't try to use email to fix the problem. They very sensibly go to the web site and try by phone or Twitter or some other medium that isn't the one that isn't working.

postmaster@ exists for many, many more reasons than non-deliverability. Again, multiple RFCs dictate its existence and management. Advice to the contrary demands a better rationale than you're providing, and is ill-advised.

If you operate SMTP and I can't get through to you on postmaster@ ("yo, back off your retries," for example), I'm probably going to blacklist you. I'm not unique in the slightest. The decentralized nature of SMTP demands that I have a hotline to you, the MX operator, without having to navigate a Web site to maybe find you.

Re: Security.txt

#19
post #11

I think humans.txt ( http://humanstxt.org/ ) fits more, and already exists.

> It's an initiative for knowing the people behind a website. It's a TXT file that contains information about the different people who have contributed to building the website.

Not sure why you linked that, it doesn't fit at all. They're solving completely different problems.

Re: Security.txt

#20
post #12

I seem to remember suggesting jobs.txt as a listing for a company’s open positions. Someone even made a site promoting the idea. What I mean to say is that the concept of a domain is much deeper than html, and we use it so shallowly. The web is distributed and simple if we want it back.

Can you expand more on this? What do you mean by “much deeper than html”?

He means if you have a domain you can pretty much serve whatever you want off of it.
Post reply on HN