Live data from Hacker News

Security.txt

securitytxt.org

141–148 of 148 posts

Re: Security.txt

#141
post #67

Good luck getting this adopted. A couple of months ago I was trying to responsibly disclose the complete exposure of every customer's name, email address, phone number and the last four digits of their credit card to a public QSR company that allows online orders. It was straightforward enough that I found it passively while trying to login. It took over a week of me searching the website for a security page, trying…

It doesn't handle liability, and really nothing does other than the company in question doing the right thing (e.g. running a bug bounty via a well known third party and signing legal docs, or making public statements backed with documents.

Also Occams razor, a lot of websites are hell to navigate and find the security reporting contact information. Why not make it super easy?

Re: Security.txt

#142
post #64

I don't think this is fully baked. Most importantly: there are no formal definitions for what these disclosure terms mean, the distinctions between them are not unimportant, and the most important distinctions have nothing at all to do with "disclosure". To me, as a working professional in this field, "disclosure: full" informs me that if I report a vulnerability in your service, you'll publish some sort of public ad…

Regarding your analysis as to the actual usefulness of this spec - or lack thereof - I agree. There's not much substance or detail; the result seems like the bullet points of an initial PowerPoint presentation for such a concept, rather than the final output of a panel attempting to create a proposal meant to be seriously considered and adopted.

As for the rest of your comment... are you really a "working professional in this field"? By that I'm asking whether you are self-employed and playing fast and loose according to your own rules, or if you instead have an established career within the industry for which your professional peers stand beside your methods? I have to believe that honest professionals with a shred of reputability in this field would not be advocating that playing nice, so to speak, is some altruistic gift on the part of the researcher. "Security Researchers", quoted to loosely include "rogue" grey and black hats who think they have free reign to hack in any way they see fit, have gone to jail for what you appear to be claiming is a risk-free "right". It's not black and white, and the courts seem to favour whichever side suits their fancy in each individual case.

It really bothers me to see anyone suggest that any public port on a machine is 100% free reign to abuse. If public-facing access is all it takes to be free game, then I must be morally and legally in the right to pick the door locks of private citizens and businesses, or peel off the face of any ATM in an effort to "gauge its security". The loophole excuse is that the Computer Fraud and Abuse Act, in theory, only covers computer owned by the government and financial institutions. When all moral obligations are ignored, and skirting around lacklustre laws is the only defence, the intentions of some "researchers" quickly become questionable.

Your stance on the subject is probably fairly common in terms of what people want to be labelled as fair game, while in the real world researchers have to dial back a bit and play nice in order to maintain an ounce of respect in the field.

Re: Security.txt

#143
post #107
post #104

Earlier quoted context omitted.

> You can state your preference that I coordinate with you... but you can't dictate that to me --- and the suggestion that you could is presumptuous and rude. I think you are in the minority on this. If the hacker community go too far in this direction don't be surprised if there are calls to reign it in with legislation.

If I find a bug on my own I can do as I please with it. I have no obligation to inform the vendor. I can write an exploit and publish it, share it with my friends, or sell knowledge of it to whomever I please. The vendor has zero right to my work or to dictate what I do with it. There are few things more frustrating than dealing with a vendor that doesn't understand this. On the other hand, if I find something while…

There's right and there's right thing. The right is something that if you go against it, you are violating the law and can be punished by the police, courts, etc. But the right thing is much wider - there is myriad of things which are legal but not the right thing to do. The right thing is regulated by community norms and culture. Responsible disclosure is that kind of thing. It's not unlawful, but it is a becoming more and more a community norm.

Now, people that try to legislate community norms - outside of obvious cases like prohibiting murder - usually make things worse. But ignoring community norms is also not a smart thing to do.

Re: Security.txt

#144
post #64

I don't think this is fully baked. Most importantly: there are no formal definitions for what these disclosure terms mean, the distinctions between them are not unimportant, and the most important distinctions have nothing at all to do with "disclosure". To me, as a working professional in this field, "disclosure: full" informs me that if I report a vulnerability in your service, you'll publish some sort of public ad…

Regarding your analysis as to the actual usefulness of this spec - or lack thereof - I agree. There's not much substance or detail; the result seems like the bullet points of an initial PowerPoint presentation for such a concept, rather than the final output of a panel attempting to create a proposal meant to be seriously considered and adopted. As for the rest of your comment... are you really a "working professiona…

Read what he typed again, you didn't get it the first time. He was pretty clear, in CAPS LOCK LETTERS NO LESS, that the problem here was that this policy was miscommunicating what can be done, as you put it "It really bothers me to see anyone suggest that any public port on a machine is 100% free reign to abuse." He was very very clear that he believes you have 0% right to do that, and that the system proposed in the OP would encourage people to do that, that was his BIG problem with it, so you completely misread what he said (or I suspect, stopped halfway through, about on his fifth paragraph).

His comment on responsible disclosure is about the other part of the industry. The one where you install a vendors software on your machine, or where you analyze client code with out their server. As a researcher you have zero responsibility to play nice with the distributors of that content. That's like saying movie reviewers can only print reviews of already released movies on a schedule and in a way approved by the studios (certainly studios - and software companies - are allowed to make deals - contracts - with reviewers for embargoed, or even private, reviews of content before it's released).

Re: Security.txt

#145
post #64

I don't think this is fully baked. Most importantly: there are no formal definitions for what these disclosure terms mean, the distinctions between them are not unimportant, and the most important distinctions have nothing at all to do with "disclosure". To me, as a working professional in this field, "disclosure: full" informs me that if I report a vulnerability in your service, you'll publish some sort of public ad…

Regarding your analysis as to the actual usefulness of this spec - or lack thereof - I agree. There's not much substance or detail; the result seems like the bullet points of an initial PowerPoint presentation for such a concept, rather than the final output of a panel attempting to create a proposal meant to be seriously considered and adopted. As for the rest of your comment... are you really a "working professiona…

> are you really a "working professional in this field"?

> I'm asking [...] if you [...] have an established career within the industry for which your professional peers stand beside your methods?

I'm not sure if you're already aware of tptacek's reputation in the field and you're hinting at something different, or if you're asking these questions in a more direct sense. If the latter, I'd recommend checking out his profile and quickly Googling.

> in the real world researchers have to dial back a bit and play nice in order to maintain an ounce of respect in the field.

Despite what I mentioned above, it may be that this is actually true; that Thomas' reputation gives him a certain level of immunity whereas most "normal" researchers would have to stick to a stricter level of etiquette.

All said though, I think SolarNet may also be correct that you seem to have misinterpreted at least some of Thomas' post.

Re: Security.txt

#146
how about just put the right address in whois information??? >.> ... if you gonna put it on the public internet anyhow might aswell use the age old mechanism already in place to do this...

Re: Security.txt

#147

how about just put the right address in whois information??? >.> ... if you gonna put it on the public internet anyhow might aswell use the age old mechanism already in place to do this...

I don't understand why businesses use use private WHOIS services. Surely if you're a business you'll have public contact information? I was once tasked with trying to get in touch with a company who's domain name had expired, but with no website (read: contact page) or real email address in the WHOIS I had to give up.

Re: Security.txt

#148

Earlier quoted context omitted.

Regarding your analysis as to the actual usefulness of this spec - or lack thereof - I agree. There's not much substance or detail; the result seems like the bullet points of an initial PowerPoint presentation for such a concept, rather than the final output of a panel attempting to create a proposal meant to be seriously considered and adopted. As for the rest of your comment... are you really a "working professiona…

> are you really a "working professional in this field"? > I'm asking [...] if you [...] have an established career within the industry for which your professional peers stand beside your methods? I'm not sure if you're already aware of tptacek's reputation in the field and you're hinting at something different, or if you're asking these questions in a more direct sense. If the latter, I'd recommend checking out his…

>tptacek's reputation

Could you explain? I never really understood him as an individual & he's been... well, harsh at times to me & others.

Post reply on HN