Earlier quoted context omitted.
In most (all?) European countries comma is the decimal separator
Not in e.g. UK.
SecurityBaseline.eu
61–70 of 112 posts
Re: SecurityBaseline.eu
#62Re: SecurityBaseline.eu
#63Colouring an area red because they don't have DNSSEC enabled on a domain seems excessive. A nice addition would be to add who is hosting their email. First handful I've looked at are all outlook.com, which seems a much bigger privacy & security risk than not using DNSSEC.
We already have some privacy metrics in addition to tracking cookies, and there will be more. All are important at the same time.
Re: SecurityBaseline.eu
#64Colouring an area red because they don't have DNSSEC enabled on a domain seems excessive. A nice addition would be to add who is hosting their email. First handful I've looked at are all outlook.com, which seems a much bigger privacy & security risk than not using DNSSEC.
Re: SecurityBaseline.eu
#65I hate consent banners more than tracking cookies.
Re: SecurityBaseline.eu
#66There should be a metric for sites hosting malicious content! https[:]//erasmus-plus.ec.europa.eu/sites/default/files/2026-05/mortal-kombat-2-cs.pdf
Might be worth enclosing that URL in quotes or using [dot] in the URL instead, so people don't accidentally click on that "mortal-kombat-2-cs.pdf" file that Europa.EU is hosting. VirusTotal claims the PDF file is clean, but I don't think I'd fully trust it anyway. If you do find malicious content, could be worth submitting the URLs to VirusTotal so that the domain is flagged by browsers (eg Google SafeBrowsing) and p…
Just to be safe, couldn't we globally disable BGP and internet transit in general in the meantime? In case someone tries to visit it by other means?
Re: SecurityBaseline.eu
#67Colouring an area red because they don't have DNSSEC enabled on a domain seems excessive. A nice addition would be to add who is hosting their email. First handful I've looked at are all outlook.com, which seems a much bigger privacy & security risk than not using DNSSEC.
Not making it red would downplay the "SEC" part in DNSSEC. We already have some privacy metrics in addition to tracking cookies, and there will be more. All are important at the same time.
Re: SecurityBaseline.eu
#68Interesting data set. Would be interesting to repeat the same for SMEs. In my experience, Germany is pretty hopelessly behind on everything except GDPR enforcement. They are kings of that. Must have a cookie screen, apparently. That's why they score so good on that and not much else. When the GDPR became active eight or so years ago, we got a few GDPR related requests to our service. Basically strongly worded request…
Re: SecurityBaseline.eu
#69Colouring an area red because they don't have DNSSEC enabled on a domain seems excessive. A nice addition would be to add who is hosting their email. First handful I've looked at are all outlook.com, which seems a much bigger privacy & security risk than not using DNSSEC.
Something like this? https://livenson.github.io/mxmap/
A few countries have those, here's a Github repo of the Swiss one (has a list of forks in there too): https://github.com/davidhuser/mxmap
Re: SecurityBaseline.eu
#70Might this be because any kind of genuine pentesting, unless it's explicitly been paid for, is highly illegal in countries like Germany (§ 202c StGB, § 202a StGB, etc.)? For example, I'd be more than happy to pentest some govt websites here in Germany, if the very act of visiting them with a non-standard browser couldn't somehow already be misconstrued as breaking various hacking laws. No thanks! Keep your security v…
In Germany we have the completely wrong mindset for such things. Instead of being grateful, all we care about is "whose fault is it" and CYA tactics. And no one wants to be "guilty" or have their incompetence revealed, so suits will do anything they can to avoid that. Somethings serious needs to go wrong first, so that loss of face already happens, before anyone will move. Maybe we need to get hacked by Russia a few…