Live data from Hacker News

SecurityBaseline.eu

internetcleanup.foundation

81–90 of 112 posts

Re: SecurityBaseline.eu

#81
post #51

Colouring an area red because they don't have DNSSEC enabled on a domain seems excessive. A nice addition would be to add who is hosting their email. First handful I've looked at are all outlook.com, which seems a much bigger privacy & security risk than not using DNSSEC.

Not making it red would downplay the "SEC" part in DNSSEC. We already have some privacy metrics in addition to tracking cookies, and there will be more. All are important at the same time.

I'd have hoped in 2026 that anyone publishing this type of report would understand that DNSSEC isn't helping anything, and is generally considered to be actively harmful to enable. I'd suggest doing a bit more research and dropping the DNSSEC stuff, or reversing it entirely.

Re: SecurityBaseline.eu

#82
post #2

Today we launch SecurityBaseline: monitoring 67.000 governments and 200.000 sites. Headlines: 3.000 governmental sites use tracking cookies illegally, over 1.000 database management interfaces are publicly reachable, 99% of governmental email is poorly encrypted.

Q: would you mark google.com with any "high risk" findings? there are quite a few like this, that on close inspection, are just fine

I see some 25 French municipal sites are on "sites.google.com". By default we also import and attribute the main domain google.com to those organizations. That is usually correct, but obviously wrong in this case.

The data was removed, and tomorrow's reports will reflect that.

Re: SecurityBaseline.eu

#83
post #51

Colouring an area red because they don't have DNSSEC enabled on a domain seems excessive. A nice addition would be to add who is hosting their email. First handful I've looked at are all outlook.com, which seems a much bigger privacy & security risk than not using DNSSEC.

Not making it red would downplay the "SEC" part in DNSSEC. We already have some privacy metrics in addition to tracking cookies, and there will be more. All are important at the same time.

[deleted]

Re: SecurityBaseline.eu

#84
post #53
post #44

Earlier quoted context omitted.

In most (all?) European countries comma is the decimal separator

I skimmed https://wikipedia.org/wiki/Decimal_separator but still don't understand. Why does this difference exist? Also, why did the conflict eventually settle into something between full stops and commas? What stopped other symbols from continued usage like bars or underscores? It seems weird that a system would eventually settle on just full stops and commas, yet not settle on where to put them. If your system is g…

> Why does this difference exist?

Same reason why there are different date formats, weeks start on Sundays/Mondays (or Saturdays), long/short scale numbers, drives on left/right, different wall sockets and plugs, different train gauges, and of course metric/imperial.

It's a mix of tradition, conventions, inertia.

Re: SecurityBaseline.eu

#85

Earlier quoted context omitted.

Q: would you mark google.com with any "high risk" findings? there are quite a few like this, that on close inspection, are just fine

I see some 25 French municipal sites are on "sites.google.com". By default we also import and attribute the main domain google.com to those organizations. That is usually correct, but obviously wrong in this case. The data was removed, and tomorrow's reports will reflect that.

the question is: if `https://www.google.com` were to be included in this analysis, would you expect to see any "high risk" findings?

and the reason i ask is that some of the findings, i have seen, would apply to google.com, yet no one would consider them "high risk", so why do this to other services?

this effort would be better served by raising attention to truly important issues, or defects, than to try to identify as many problems as possible, and for lack of a better word, presenting the results in a away that's unnecessarily dramatic

Re: SecurityBaseline.eu

#86
post #53

Earlier quoted context omitted.

I skimmed https://wikipedia.org/wiki/Decimal_separator but still don't understand. Why does this difference exist? Also, why did the conflict eventually settle into something between full stops and commas? What stopped other symbols from continued usage like bars or underscores? It seems weird that a system would eventually settle on just full stops and commas, yet not settle on where to put them. If your system is g…

Because in English you say "three dot two", whereas in German it is "Drei-Komma-Zwei". It just reflects the spoken language. And having the unused symbol then be the thousand separator is natural.

Interesting, I did not know this, but a little bit doubtful. Wouldn't it be the other way around? Explicit spoken language coming from being written that way.

Re: SecurityBaseline.eu

#87
post #86

Earlier quoted context omitted.

Because in English you say "three dot two", whereas in German it is "Drei-Komma-Zwei". It just reflects the spoken language. And having the unused symbol then be the thousand separator is natural.

Interesting, I did not know this, but a little bit doubtful. Wouldn't it be the other way around? Explicit spoken language coming from being written that way.

Maybe at some point originally, but now you can't change it. Spoken language resists attempts to shape it by committee, and written language has to begrudgingly follow its lead.

Re: SecurityBaseline.eu

#90
post #55
post #8

Honestly surprised that Italian municipalities are doing relatively well compared to other countries. Maybe it helped a push from the government to have a shared design for municipal websites ( https://github.com/orgs/italia/repositories?q=comuni )

Italians stay winning as usual... :-) But for real, Italian public administration digitalization isn’t as bad as people think when compared to other big countries. SPID (an electronic identity system, now deprecated) was years ahead of many other European countries (and easily, the US), and PEC (a certified email standard for official communications established in 2005, that can be used with standard email clients) i…

It's almost as if putting competent people in the right place and with the right budget is the best way to achieve government/public-funded results...
Post reply on HN