Live data from Hacker News

Security.txt

securitytxt.org

31–40 of 148 posts

Re: Security.txt

#31
post #11

I think humans.txt ( http://humanstxt.org/ ) fits more, and already exists.

I've never heard of this. I wonder how many websites implement this. I tried a bunch of sites, but the only one I could find that had a humans.txt file was google: Google is built by a large team of engineers, designers, researchers, robots, and others in many different sites across the globe. It is updated continuously, and built with more tools and technologies than we can shake a stick at. If you'd like to help us…

Here's two examples: https://medium.com/humans.txt, https://www.python.org/humans.txt.

Re: Security.txt

#32
post #11

I think humans.txt ( http://humanstxt.org/ ) fits more, and already exists.

I've never heard of this. I wonder how many websites implement this. I tried a bunch of sites, but the only one I could find that had a humans.txt file was google: Google is built by a large team of engineers, designers, researchers, robots, and others in many different sites across the globe. It is updated continuously, and built with more tools and technologies than we can shake a stick at. If you'd like to help us…

https://www.google.com/humans.txt

Re: Security.txt

#34
post #11

I think humans.txt ( http://humanstxt.org/ ) fits more, and already exists.

I've never heard of this. I wonder how many websites implement this. I tried a bunch of sites, but the only one I could find that had a humans.txt file was google: Google is built by a large team of engineers, designers, researchers, robots, and others in many different sites across the globe. It is updated continuously, and built with more tools and technologies than we can shake a stick at. If you'd like to help us…

We do: https://esharesinc.com/humans.txt

It's part of every new engineer's first day or two. It's their first shipped PR to add themselves as a human.

Re: Security.txt

#35
post #11

I think humans.txt ( http://humanstxt.org/ ) fits more, and already exists.

> It's an initiative for knowing the people behind a website. It's a TXT file that contains information about the different people who have contributed to building the website. Not sure why you linked that, it doesn't fit at all. They're solving completely different problems.

[deleted]

Re: Security.txt

#36
post #21

If you have a disclosure policy, chances are googling "company name + disclosure" will bring it up. Don't really see benefits of standardising this, not going to help any companies that previously had no disclosure policies decide to implement one and "discoverability of existing disclosure policies" doesn't really seem like a big issue.

Enables automated vulnerability disclosure.

Re: Security.txt

#37
This site is horribly complex for creating a plain-text file with four fields. Perhaps, the complexity comes from having 10 contributors.

_Not everything needs to be a large project._ A template right on the webpage would have the same value. That raises the point that a blog post about the RFC would have greater utility.

Re: Security.txt

#38
post #21

If you have a disclosure policy, chances are googling "company name + disclosure" will bring it up. Don't really see benefits of standardising this, not going to help any companies that previously had no disclosure policies decide to implement one and "discoverability of existing disclosure policies" doesn't really seem like a big issue.

The more you use a Google feature as a crutch, the less the web is semantic.

Also, Google has increasingly made it difficult to automate searches, so the effort required to notify multiple websites increases quickly.

Re: Security.txt

#40

As an operator of many websites... I don't want more emails from "Security Researchers" who want $100 to tell me the obvious such as, "Login form should be rate-limited" or "emails can be enumerated using password reset form" and the like... Instead, we should have a central vulnerability repository that is open-source, standardized, public, and transparent. This repository should vet vulnerability reports before con…

> Instead, we should have a central vulnerability repository that is open-source, standardized, public, and transparent. This repository should vet vulnerability reports before contacting the software owner prior to disclosure.

There are plenty of those. Generally, they take a cut of the bounty.

Post reply on HN