Live data from Hacker News

SecurityBaseline.eu

internetcleanup.foundation

101–110 of 112 posts

Re: SecurityBaseline.eu

#101
post #2

Today we launch SecurityBaseline: monitoring 67.000 governments and 200.000 sites. Headlines: 3.000 governmental sites use tracking cookies illegally, over 1.000 database management interfaces are publicly reachable, 99% of governmental email is poorly encrypted.

> 3.000 governmental sites use tracking cookies illegally

In the USA the government often excludes itself from privacy and other similar laws, did the EU fail to make that distinction?

Re: SecurityBaseline.eu

#102

Earlier quoted context omitted.

How is the home of chaos computer club so bad at this....

There is a kind of naiveté, also at EU level, where people think that once it's a law, bad actors will just fold. They minds are somehow unable to comprehend that only the good actors will fold and only bad actors will be left. Other examples are: Firearms possession, supply chain law regarding human rights and child labor.

I was really excited for GDPR until I realized Europe had no intention of actually enforcing it :-(

Re: SecurityBaseline.eu

#103

Earlier quoted context omitted.

Not making it red would downplay the "SEC" part in DNSSEC. We already have some privacy metrics in addition to tracking cookies, and there will be more. All are important at the same time.

I'd have hoped in 2026 that anyone publishing this type of report would understand that DNSSEC isn't helping anything, and is generally considered to be actively harmful to enable. I'd suggest doing a bit more research and dropping the DNSSEC stuff, or reversing it entirely.

DNSSEC is more likely to self-DoS yourself than protect against an attack, unfortunately.

Re: SecurityBaseline.eu

#104

Earlier quoted context omitted.

I'd have hoped in 2026 that anyone publishing this type of report would understand that DNSSEC isn't helping anything, and is generally considered to be actively harmful to enable. I'd suggest doing a bit more research and dropping the DNSSEC stuff, or reversing it entirely.

DNSSEC is more likely to self-DoS yourself than protect against an attack, unfortunately.

as exemplified by the recent .de outage https://www.theregister.com/networks/2026/05/06/denic-sorry-...

Re: SecurityBaseline.eu

#105
post #51

Colouring an area red because they don't have DNSSEC enabled on a domain seems excessive. A nice addition would be to add who is hosting their email. First handful I've looked at are all outlook.com, which seems a much bigger privacy & security risk than not using DNSSEC.

> A nice addition would be to add who is hosting their email. Something like this? https://livenson.github.io/mxmap/ A few countries have those, here's a Github repo of the Swiss one (has a list of forks in there too): https://github.com/davidhuser/mxmap

Thanks for that link! The results are predictably depressing.

Re: SecurityBaseline.eu

#106

Earlier quoted context omitted.

There is a kind of naiveté, also at EU level, where people think that once it's a law, bad actors will just fold. They minds are somehow unable to comprehend that only the good actors will fold and only bad actors will be left. Other examples are: Firearms possession, supply chain law regarding human rights and child labor.

I was really excited for GDPR until I realized Europe had no intention of actually enforcing it :-(

Actually, southern europe seems to have understood that it can be quite a good business fining US megacorps billions and billions. Northern european countries do very little except symbolic wrist slapping.

Re: SecurityBaseline.eu

#107
post #51

Colouring an area red because they don't have DNSSEC enabled on a domain seems excessive. A nice addition would be to add who is hosting their email. First handful I've looked at are all outlook.com, which seems a much bigger privacy & security risk than not using DNSSEC.

Not making it red would downplay the "SEC" part in DNSSEC. We already have some privacy metrics in addition to tracking cookies, and there will be more. All are important at the same time.

It is not desirable to have mass adoption of DNSSEC, or to try to incentivize that.

Re: SecurityBaseline.eu

#108

Earlier quoted context omitted.

I was really excited for GDPR until I realized Europe had no intention of actually enforcing it :-(

Actually, southern europe seems to have understood that it can be quite a good business fining US megacorps billions and billions. Northern european countries do very little except symbolic wrist slapping.

Sure, but there were other provisions like machine-readability of exported data, etc. that could have been really helpful. I should be able to do a one-click export of my Spotify playlists and favourites (the music I like is personal info in my view) in to Qobuz, for instance.

"The data subject shall have the right to receive the personal data concerning him or her, which he or she has provided to a controller, in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller without hindrance from the controller to which the personal data have been provided"

https://gdpr-library.com/article/20

Re: SecurityBaseline.eu

#109

Earlier quoted context omitted.

> Germany is pretty hopelessly behind on everything except GDPR enforcement. Are you sure? I see major outlets in Germany blatantly violating the GDPR by forcing visitors to pay with their privacy or pay with their money. That is not allowed. It is perfectly fine to have a paywall, but you can never have people pay with their privacy.

Are you sure they are in violation? Because it only takes one customer to trigger expensive lawsuits. And there are a lot of very eager and trigger happy lawyers in Germany specializing in that sort of thing. A lot of people make bad assumptions about what is and isn't legal/allowed and a lot of companies have gotten good at finding the grey area of stuff that probably won't get them into trouble.

From a quick check some wrong ones seem to have disappeared, but bild.de is massively confusing right now. It offers

  > Um BILD.de kostenfrei nutzen zu können, ist für einige Verarbeitungszwecke Ihre Einwilligung erforderlich. Für andere Verarbeitungszwecke können Sie hier eine Auswahl treffen. Wenn Sie zu allen Verarbeitungszwecken eine Auswahl getroffen haben, können Sie diese speichern. Sie können Ihre Auswahl jederzeit über den Link „Privacy-Manager“ ändern.

That seems in violation of: privacy is not a payment.

EDIT: bild.de offers a fake consent choice screen. They fail to provide a "decline all" next to their "accept all" option, but even if you disable every tracking choice and choose to persist your choices, it does nothing and keeps the blocking cookie wall.

Re: SecurityBaseline.eu

#110
post #100

Earlier quoted context omitted.

The mere act of scanning for vulnerability often causes outages. I once ran a vulnerability scan at an industrial company that completely disabled their employees ability to clock in and out. I didnt believe it had anything to do with my scanner at first, but it ran on a schedule and the scanners schedule matched their outages eaxctly. Eventually it turned out the timecard system had these IOT badge readers with a po…

But in a perfect world, the question would be: Is it reasonable to expect an outage by sending a few single TCP packet to a system? Or, were you flooding the system unreasonably? It is a huge security risk to treat systems as ancient eggshells you must not touch ever. A certain amount of touching has to be reasonable, because that is what foreign actors will do if they need to cause trouble. Apparently you could caus…

> Is it reasonable to expect an outage by sending a few single TCP packet to a system?

Thats kind of the rub isn't it? If I'm authorized to do the scan its reasonable. If I'm unauthorized nothing I do is reasonable.

It' similar to drivers licenses. If you get in an accident that wasn't your fault, but your license was invalid, its still your fault legally because you weren't meant to be on the road at all.

Post reply on HN