Live data from Hacker News

SecurityBaseline.eu

internetcleanup.foundation

61–70 of 112 posts

Re: SecurityBaseline.eu

#62

Earlier quoted context omitted.

Oh no way. First, replace fahrenheit to celsius, then miles to kms and we are all set to a nice, unified future.

I much prefer a 60mi commute to a 96km commute. It is less depressing.

So you live in a constant mirage, a delusional reality? :)

Re: SecurityBaseline.eu

#63
post #51

Colouring an area red because they don't have DNSSEC enabled on a domain seems excessive. A nice addition would be to add who is hosting their email. First handful I've looked at are all outlook.com, which seems a much bigger privacy & security risk than not using DNSSEC.

Not making it red would downplay the "SEC" part in DNSSEC.

We already have some privacy metrics in addition to tracking cookies, and there will be more. All are important at the same time.

Re: SecurityBaseline.eu

#64
post #51

Colouring an area red because they don't have DNSSEC enabled on a domain seems excessive. A nice addition would be to add who is hosting their email. First handful I've looked at are all outlook.com, which seems a much bigger privacy & security risk than not using DNSSEC.

[dead]

Re: SecurityBaseline.eu

#66
post #21

There should be a metric for sites hosting malicious content! https[:]//erasmus-plus.ec.europa.eu/sites/default/files/2026-05/mortal-kombat-2-cs.pdf

Might be worth enclosing that URL in quotes or using [dot] in the URL instead, so people don't accidentally click on that "mortal-kombat-2-cs.pdf" file that Europa.EU is hosting. VirusTotal claims the PDF file is clean, but I don't think I'd fully trust it anyway. If you do find malicious content, could be worth submitting the URLs to VirusTotal so that the domain is flagged by browsers (eg Google SafeBrowsing) and p…

> people can't accidentally visit ec.europa.eu domains until it has been cleaned

Just to be safe, couldn't we globally disable BGP and internet transit in general in the meantime? In case someone tries to visit it by other means?

Re: SecurityBaseline.eu

#67
post #51

Colouring an area red because they don't have DNSSEC enabled on a domain seems excessive. A nice addition would be to add who is hosting their email. First handful I've looked at are all outlook.com, which seems a much bigger privacy & security risk than not using DNSSEC.

Not making it red would downplay the "SEC" part in DNSSEC. We already have some privacy metrics in addition to tracking cookies, and there will be more. All are important at the same time.

"Important" according to whom? A tracking cookie is trivial to fix (or to automagically disable for the more tech savvy citizens). Email being hosted by an untrusted foreign corporation is way harder to fix and impossible to bypass as a citizen trying to contact their government.

Re: SecurityBaseline.eu

#68

Interesting data set. Would be interesting to repeat the same for SMEs. In my experience, Germany is pretty hopelessly behind on everything except GDPR enforcement. They are kings of that. Must have a cookie screen, apparently. That's why they score so good on that and not much else. When the GDPR became active eight or so years ago, we got a few GDPR related requests to our service. Basically strongly worded request…

Actually Spain leaded on this and had strictest regulations before Germany regulated broader "Neuland" Cookies.

Re: SecurityBaseline.eu

#69
post #51

Colouring an area red because they don't have DNSSEC enabled on a domain seems excessive. A nice addition would be to add who is hosting their email. First handful I've looked at are all outlook.com, which seems a much bigger privacy & security risk than not using DNSSEC.

> A nice addition would be to add who is hosting their email.

Something like this? https://livenson.github.io/mxmap/

A few countries have those, here's a Github repo of the Swiss one (has a list of forks in there too): https://github.com/davidhuser/mxmap

Re: SecurityBaseline.eu

#70
post #24

Might this be because any kind of genuine pentesting, unless it's explicitly been paid for, is highly illegal in countries like Germany (§ 202c StGB, § 202a StGB, etc.)? For example, I'd be more than happy to pentest some govt websites here in Germany, if the very act of visiting them with a non-standard browser couldn't somehow already be misconstrued as breaking various hacking laws. No thanks! Keep your security v…

In Germany we have the completely wrong mindset for such things. Instead of being grateful, all we care about is "whose fault is it" and CYA tactics. And no one wants to be "guilty" or have their incompetence revealed, so suits will do anything they can to avoid that. Somethings serious needs to go wrong first, so that loss of face already happens, before anyone will move. Maybe we need to get hacked by Russia a few…

You still have quite enough people in high places who are direct or indirect beneficiaries of companies that are either Russian or tied to Russia, so nothing will ever happen even then.
Post reply on HN