Live data from Hacker News

SecurityBaseline.eu

internetcleanup.foundation

41–50 of 112 posts

Re: SecurityBaseline.eu

#43
post #2

Today we launch SecurityBaseline: monitoring 67.000 governments and 200.000 sites. Headlines: 3.000 governmental sites use tracking cookies illegally, over 1.000 database management interfaces are publicly reachable, 99% of governmental email is poorly encrypted.

Q: would you mark google.com with any "high risk" findings?

there are quite a few like this, that on close inspection, are just fine

Re: SecurityBaseline.eu

#46
post #21

There should be a metric for sites hosting malicious content! https[:]//erasmus-plus.ec.europa.eu/sites/default/files/2026-05/mortal-kombat-2-cs.pdf

Might be worth enclosing that URL in quotes or using [dot] in the URL instead, so people don't accidentally click on that "mortal-kombat-2-cs.pdf" file that Europa.EU is hosting. VirusTotal claims the PDF file is clean, but I don't think I'd fully trust it anyway. If you do find malicious content, could be worth submitting the URLs to VirusTotal so that the domain is flagged by browsers (eg Google SafeBrowsing) and p…

The domain is legitimate though.

Re: SecurityBaseline.eu

#47
I checked Warsaw, Poland.

It has 3 HIGH RISK issues because

    - DNSSEC is not configured
    - Few cookies are send and (ALERT!) Google marketing cookie
    - Missing ROA
The thing though is that this is purely informational website (that's defunct under Safari :D) and all actual interaction goes through specialized portal (e.g. gov.pl, for which only complain is cipher order).

I get it, it's aggregator but showing red maps is at leals sensationalists

Seems that results are taken from internet.nl, which has WAY better UI than page posted.

https://batch.internet.nl/site/um.warszawa.pl/17768032/#

Re: SecurityBaseline.eu

#48
post #24

Might this be because any kind of genuine pentesting, unless it's explicitly been paid for, is highly illegal in countries like Germany (§ 202c StGB, § 202a StGB, etc.)? For example, I'd be more than happy to pentest some govt websites here in Germany, if the very act of visiting them with a non-standard browser couldn't somehow already be misconstrued as breaking various hacking laws. No thanks! Keep your security v…

Yeah.

And I do think that security research should have some regulation about it, but it should be more about responsible handling of the privileged access you gained, or a responsibility to disclose found vulnerabilities in private and/or to a government entity. You know, "If you have gained access to a system, and you saw a button and you pressed it, you are on the hook for the damages". That is common practice with paid pentesters already.

But we're at a point where a court had do decide if discovering an endpoint on an API without authorization is a "circumvention of a security boundary" or not. Luckily, we now have a ruling that accessing API endpoints without authorization logic is no circumvention of a security boundary, due to a lack of a security boundary like authorization.

That's the level we are at. I don't want to know what happens if foreign nation state actors start acting on this seriously.

Post reply on HN