Live data from Hacker News

Security.txt

securitytxt.org

131–140 of 148 posts

Re: Security.txt

#131
post #9

Should surely be .well-known/security.txt, or if not explain why not. rfc5785 "Defining Well-Known Uniform Resource Identifiers (URIs)" [edit: I see the FAQ says that, while the linked Internet Draft says it goes at top-level like robots.txt]

I had only seen ".well-known/" used by Let's Encrypt, and wasn't aware that it was part of a larger (proposed) standard. Thank you for mentioning it.

For others who are interested, here a detailed description: https://tools.ietf.org/html/rfc5785

Re: Security.txt

#132

Earlier quoted context omitted.

This is utterly maddening. I had a similar experience, except that at first they didn't believe me regarding the vulnerability. I basically said, "cool, I'm glad it's not a problem, so when I release the deets and write up a blog post you have nothing to worry about ;-)" After they finally acknowledged the problem they started treating me like I was a criminal who attacked them. I strictly follow responsible disclosu…

Yup. They often claim you’re “malicious” to cover their incompetent butts. This is why reporting should be: - end-to-end encrypted with a brand new, limited-time GPG key - use a disposable email service - make up an alias - send from public WiFi at a coffeeshop some distance away that doesn’t have corporate CCTV - Don’t bother with Tor or a VPN because it advertises “suspicious behavior” across network hops that mayb…

IMO, the problem with disclosure is one of the biggest problems with infosec right now...

Re: Security.txt

#133
post #121

Earlier quoted context omitted.

Done. Thank you for the advice, and all your security work. https://github.com/joelparkerhenderson/coordinated_disclosur... If you have anything more you want in it, please let me know.

Isn't responsible disclosure the aim here? I don't think substituting coordination for responsible is a sensible strategy for your project. The coordination is inherit from the fact that they are honouring your disclosure policy. The word coordinated is redundant. Objectively, it should be called a "security disclosure" policy.

You make good points.

How would you improve it to clarify the aim is to be generally useful for both sides?

For example, when I personally discover a security issue, I want to be able to report it to a company, and also include a link to this doc, and ask "Here's how I suggest we interact and why; what do you think?".

Re: Security.txt

#134

Earlier quoted context omitted.

>In my life, I have only reported two different vulnerabilities to two different vendors. Interesting. I don't think this is for you. Ever have the task of needing to report a security issue to 10k sites and wish you could have any hope of automating it? I certainly haven't. More like 100k! Don't be so negative when people try to do good.

You needed to contact 100k sites about security? Do you have more details on this? The example security.txt for this site currently has a twitter handle as the contact. How are you going to automate that?

> You needed to contact 100k sites about security? Do you have more details on this?

There's a number of people out there anonymously helping others close their holes. Some holes can be easily scanned.

Re: Security.txt

#135
post #87

Earlier quoted context omitted.

One may want to notify many website owners at once that it’s a good time to apply a patch in response to a security vulnerability affecting a technology they are using. Ex: WordPress, node.js, MongoDB, etc.

There are 100s of millions of sites, who’s going to crawl all of them and send out alerts? How would you know what backend tech is being used? Major risks and CVEs are already published in the appropriate news channels, which is far more efficient and effective.

It should be, but it isn't, and more importantly, there's lots of critical infrastructure out there that is highly vulnerable.

Re: Security.txt

#136
post #121

Earlier quoted context omitted.

Done. Thank you for the advice, and all your security work. https://github.com/joelparkerhenderson/coordinated_disclosur... If you have anything more you want in it, please let me know.

Isn't responsible disclosure the aim here? I don't think substituting coordination for responsible is a sensible strategy for your project. The coordination is inherit from the fact that they are honouring your disclosure policy. The word coordinated is redundant. Objectively, it should be called a "security disclosure" policy.

Once again, "responsible disclosure" is a term of art in the industry, and it communicates something he probably doesn't mean to communicate.

Re: Security.txt

#137

Earlier quoted context omitted.

There are 100s of millions of sites, who’s going to crawl all of them and send out alerts? How would you know what backend tech is being used? Major risks and CVEs are already published in the appropriate news channels, which is far more efficient and effective.

It should be, but it isn't, and more importantly, there's lots of critical infrastructure out there that is highly vulnerable.

Who is running critical infrastructure that you cant easily reach right now? Are you saying you know of a major CVE that has no coverage?

Re: Security.txt

#138
post #127
post #126

Earlier quoted context omitted.

That argument doesn't hold up. If it did security researchers who publish findings in commercial products would all have been sued by now. Many countries have fair use exemptions to prevent copyright holders from engaging in the kind of abuse you describe.

Yes - this does happen. [1] https://www.cnet.com/news/dutch-chipmaker-sues-to-silence-se... [2] http://www.eweek.com/blogs/security-watch/german-software-co... [3] http://www.securityfocus.com/news/11259 [0] https://duckduckgo.com/?q=security+researcher+sued&t=ffsb&ia...

Yeah, companies sometimes bully and intimidate, but all those links point at baseless lawsuits that didn't legally succeed.

Re: Security.txt

#139
post #11

I think humans.txt ( http://humanstxt.org/ ) fits more, and already exists.

I was thinking the same thing. It seems the security team would be made up of humans :)
Post reply on HN