Live data from Hacker News

SecurityBaseline.eu

internetcleanup.foundation

21–30 of 112 posts

Re: SecurityBaseline.eu

#21
There should be a metric for sites hosting malicious content!

https[:]//erasmus-plus.ec.europa.eu/sites/default/files/2026-05/mortal-kombat-2-cs.pdf

Re: SecurityBaseline.eu

#22

[flagged]

Came here to say this. Absolutely insane. Why is phpMyAdmin even still needed/wanted in 2026? It's not exactly user friendly for a developer, let alone an average Gov employee...

Knowing the govt sector, the developers probably got hired 20 years ago and enjoy their stable, chill, even if a bit low pay job. No need to do CV-Driven Development and chase any new trend if the site's running and they're not looking for a new position...

Re: SecurityBaseline.eu

#24
Might this be because any kind of genuine pentesting, unless it's explicitly been paid for, is highly illegal in countries like Germany (§ 202c StGB, § 202a StGB, etc.)?

For example, I'd be more than happy to pentest some govt websites here in Germany, if the very act of visiting them with a non-standard browser couldn't somehow already be misconstrued as breaking various hacking laws. No thanks! Keep your security vulnerabilities.

Re: SecurityBaseline.eu

#26

Is there a list of these "goverment" sites anywhere? I have been working on similar project, focusing on lithuanian-only "goverment" sites, but it's not perfectly obvious how to recognise public vs private websites, as at least half of those are managed privatelly, used publically. (Mostly due that was cheaper and/or because lack of requirements and/or other weird situations.) But yeah, I can confirm that stats are s…

What we have is published on https://securitybaseline.eu/datasets openly. Some governments publish lists, and they will be incomplete. In the article we point to our most successful approach: sifting through the (partial) zone file with domain owner information. That delivered thousands of sites the Dutch government didn't even know about.

Perhaps a freedom of information request might also work, but that will take a lot of time to write correctly and does not scale across all governments.

Re: SecurityBaseline.eu

#28
post #24

Might this be because any kind of genuine pentesting, unless it's explicitly been paid for, is highly illegal in countries like Germany (§ 202c StGB, § 202a StGB, etc.)? For example, I'd be more than happy to pentest some govt websites here in Germany, if the very act of visiting them with a non-standard browser couldn't somehow already be misconstrued as breaking various hacking laws. No thanks! Keep your security v…

To be fair, most of this stuff could be found with any normal browser. You don't even need browser dev tools. But if you write a simple script to automate any of this... yeah. They can totally get you for doing that. Probably one or the best examples why politicians should not be allowed to pass technical laws they fundamentally can't grasp.

Re: SecurityBaseline.eu

#29

[flagged]

Came here to say this. Absolutely insane. Why is phpMyAdmin even still needed/wanted in 2026? It's not exactly user friendly for a developer, let alone an average Gov employee...

Clarify what is "used today" and what features phpmyadmin provided that are "no longer needed". Until then your comment is just a juvenile attack.

Re: SecurityBaseline.eu

#30
post #2

Today we launch SecurityBaseline: monitoring 67.000 governments and 200.000 sites. Headlines: 3.000 governmental sites use tracking cookies illegally, over 1.000 database management interfaces are publicly reachable, 99% of governmental email is poorly encrypted.

Maybe post this as Show HN ? And adjust headline to fit max chars.

yes
Post reply on HN