TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Security.txt file now mandatory for Dutch government websites

359 pointsby pseudotrashalmost 2 years ago

24 comments

mtmailalmost 2 years ago
&gt; The aim is that, for example, ethical hackers can immediately contact the right person or department to tackle the vulnerability.<p>We added such a file years ago. There&#x27;s still some security researchers (&quot;bug hunters&quot;) not aware of the standard and email other email addresses (info@, invoice@, data-protection@). Nobody has ever used the GPG key we list in the security.txt file. The email address we list (security@) hasn&#x27;t received any significant spam.
评论 #36149830 未加载
评论 #36149649 未加载
评论 #36149443 未加载
评论 #36149863 未加载
aequitasalmost 2 years ago
To get an idea of how well our government organisations get along with implementing this (and a lot of other basic security requirements, like TLS, IPv6, DNSSEC, etc) you can view these maps[0][1].<p>We maintain a set of open source tools to easily get you started[2]. If you would like help to have this for your country&#x2F;government&#x2F;organisation as well, feel free to contact us.<p>[0] <a href="https:&#x2F;&#x2F;basisbeveiliging.nl&#x2F;#&#x2F;metric-progress&#x2F;NL&#x2F;municipality&#x2F;internet_nl_wsm_web_appsecpriv_securitytxt" rel="nofollow">https:&#x2F;&#x2F;basisbeveiliging.nl&#x2F;#&#x2F;metric-progress&#x2F;NL&#x2F;municipalit...</a> [1] <a href="https:&#x2F;&#x2F;basisbeveiliging.nl&#x2F;#&#x2F;maps" rel="nofollow">https:&#x2F;&#x2F;basisbeveiliging.nl&#x2F;#&#x2F;maps</a> [2] <a href="https:&#x2F;&#x2F;gitlab.com&#x2F;internet-cleanup-foundation&#x2F;web-security-map" rel="nofollow">https:&#x2F;&#x2F;gitlab.com&#x2F;internet-cleanup-foundation&#x2F;web-security-...</a>
评论 #36150682 未加载
评论 #36151238 未加载
评论 #36153153 未加载
oefrhaalmost 2 years ago
This has been discussed to death every time security.txt comes up, but in my experience it&#x27;s been a great way to receive spam about bullshit &quot;vulnerabilities&quot; from low effort scanners operated by &quot;security researchers&quot;.<p>Much like how people publish email addresses online using human readable replacements (e.g. AT instead of @) to avoid spam, I&#x27;d rather put up a contact page that&#x27;s easy for humans to find but nontrivial to automate.
评论 #36149284 未加载
NoZebra120vClipalmost 2 years ago
<p><pre><code> 2.5.6. Hiring The &quot;Hiring&quot; field is used for linking to the vendor&#x27;s security-related job positions. If this field indicates a web URI, then it MUST begin with &quot;https:&#x2F;&#x2F;&quot; (as per Section 2.7.2 of [RFC7230]). </code></pre> Hey, I just found a new way to job hunt!
评论 #36149317 未加载
评论 #36149549 未加载
评论 #36149834 未加载
throwawaaarrghalmost 2 years ago
Keep in mind this is only mandatory <i>for government websites</i>. That&#x27;s a pretty low bar. If I worked for the government, or even a company that had one clear way to contact security, I would love this. I honestly have no fucking idea how to directly contact security most of the time and that&#x27;s insane because I actually want to help them.<p>I don&#x27;t care if they receive spam, I just want them to tell me how to contact them. Give me a captcha form, a phone number, an AOL Instant Messenger handle, I don&#x27;t care.
评论 #36149704 未加载
a2800276almost 2 years ago
&quot;Dutch government websites must comply with the security.txt standard from 25 May. This is announced by the Digital Trust Center of the National Government.&quot;<p>Somewhat ironically:<p><a href="https:&#x2F;&#x2F;www.digitaltrustcenter.nl&#x2F;security.txt" rel="nofollow">https:&#x2F;&#x2F;www.digitaltrustcenter.nl&#x2F;security.txt</a><p>The website of the Digital Trust Center returns 404
评论 #36150201 未加载
评论 #36150196 未加载
评论 #36150190 未加载
androidasalmost 2 years ago
Really cool. I’ve done responsible disclosure in the past and finding someone who’ll listen is probably the hardest part of it
评论 #36149094 未加载
评论 #36150415 未加载
hoofheartedalmost 2 years ago
I’m working on a simple website generator for developers and content creators.<p>I’ve already included everything a user would want for a complete website, including a robots.txt, sitemaps, perfect Lighthouse seo score, rich snippets, and a ton of other stuff.<p>Should I consider adding an auto generated security.txt file along side the robots.txt file for users?<p>Do you’all think a security.txt file is something users would want in 2023? Or would it look stupid and confusing?<p><a href="https:&#x2F;&#x2F;github.com&#x2F;elegantframework&#x2F;elegant-cli">https:&#x2F;&#x2F;github.com&#x2F;elegantframework&#x2F;elegant-cli</a>
评论 #36152473 未加载
评论 #36151419 未加载
serial_devalmost 2 years ago
Never heard about security txt files until now, but it makes a lot of sense!<p>Regulations are a hit or miss (e.g the cookie notification rules have some good parts but I wonder if there isn&#x27;t any room for improvement in the current &quot;visiting a website for 10 seconds and clicking whatever the big button is so that I see the content in interested in&quot; status quo.<p>This one is not obtrusive, easy to implement (though only developers care about this part) and solves the problem.
评论 #36149490 未加载
评论 #36149801 未加载
评论 #36149230 未加载
punnerudalmost 2 years ago
I checked the top 20 most used websites in Germany (with .de), and number 20 on the list is the first to have it: <a href="https:&#x2F;&#x2F;www.focus.de&#x2F;security.txt" rel="nofollow">https:&#x2F;&#x2F;www.focus.de&#x2F;security.txt</a><p>Most used webpages: <a href="https:&#x2F;&#x2F;www.similarweb.com&#x2F;top-websites&#x2F;germany&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.similarweb.com&#x2F;top-websites&#x2F;germany&#x2F;</a>
评论 #36150065 未加载
plugin-babyalmost 2 years ago
Should the title be “security.txt” instead of “Security.txt”?
评论 #36149208 未加载
jwilkalmost 2 years ago
security.txt discussed on HN:<p>2017: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=15416198" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=15416198</a> (145 comments)<p>2019: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=19151213" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=19151213</a> (55 comments)<p>2021: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=26455493" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=26455493</a> (167 comments)
milliamsalmost 2 years ago
I&#x27;ve just checked the UK&#x27;s GDS advice and they have it as a &quot;should&quot;: <a href="https:&#x2F;&#x2F;gds-way.cloudapps.digital&#x2F;manuals&#x2F;security-overview-for-websites.html#10-implement-security-txt" rel="nofollow">https:&#x2F;&#x2F;gds-way.cloudapps.digital&#x2F;manuals&#x2F;security-overview-...</a><p>They have more information at <a href="https:&#x2F;&#x2F;gds-way.cloudapps.digital&#x2F;standards&#x2F;vulnerability-disclosure.html" rel="nofollow">https:&#x2F;&#x2F;gds-way.cloudapps.digital&#x2F;standards&#x2F;vulnerability-di...</a> where they strengthen the advice by saving:<p><pre><code> As per the current policy, we only accept reports from services that have a security.txt file pointing to the security policy.</code></pre>
评论 #36149212 未加载
评论 #36150047 未加载
JohnFenalmost 2 years ago
Whatever happened to just having the standard &quot;abuse@domain.name&quot; email address?
baknualmost 2 years ago
The formal news release on this from the Dutch Standardization Forum can be found here: <a href="https:&#x2F;&#x2F;forumstandaardisatie.nl&#x2F;nieuws&#x2F;securitytxt-mandatory-dutch-government" rel="nofollow">https:&#x2F;&#x2F;forumstandaardisatie.nl&#x2F;nieuws&#x2F;securitytxt-mandatory...</a><p>Note that you can test if a website has valid security.txt with the Internet.nl test tool: <a href="https:&#x2F;&#x2F;en.internet.nl&#x2F;article&#x2F;securitytxt-test-toegevoegd&#x2F;" rel="nofollow">https:&#x2F;&#x2F;en.internet.nl&#x2F;article&#x2F;securitytxt-test-toegevoegd&#x2F;</a>
benatkinalmost 2 years ago
This is a win for GPG. Some, like the current PyPI maintainers, want to throw it out with no replacement. That&#x27;s a terrible idea. And I don&#x27;t see why it needs to be replaced completely.
qwertoxalmost 2 years ago
<a href="https:&#x2F;&#x2F;www.amsterdam.nl&#x2F;security.txt" rel="nofollow">https:&#x2F;&#x2F;www.amsterdam.nl&#x2F;security.txt</a> returns<p>---<p>Contact: <a href="https:&#x2F;&#x2F;www.amsterdam.nl&#x2F;privacy&#x2F;informatiebeveiliging-gemeente-amsterdam&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.amsterdam.nl&#x2F;privacy&#x2F;informatiebeveiliging-gemee...</a><p>Expires: 2024-02-01T10:00:00.000Z<p>Acknowledgments: <a href="https:&#x2F;&#x2F;www.informatiebeveiligingsdienst.nl&#x2F;?s=hall+of+fame" rel="nofollow">https:&#x2F;&#x2F;www.informatiebeveiligingsdienst.nl&#x2F;?s=hall+of+fame</a><p>Preferred-Languages: en,nl<p>---<p>rfc9116<p>2.5.1. Acknowledgments<p>The &quot;Acknowledgments&quot; field indicates a link to a page where security researchers are recognized for their reports. The page being referenced should list security researchers that reported security vulnerabilities and collaborated to remediate them. Organizations should be careful to limit the vulnerability information being published in order to prevent future attacks.<p>If this field indicates a web URI, then it MUST begin with &quot;<a href="https:&#x2F;&#x2F;" rel="nofollow">https:&#x2F;&#x2F;</a>&quot; (as per Section 2.7.2 of [RFC7230]).
foxbytealmost 2 years ago
Really appreciated this article - it&#x27;s high time the Dutch government websites took steps like these towards strengthening their security! Still, they could definitely do with a bit more user-friendly explanations, so everyone can understand the importance of initiatives like security.txt.
yreadalmost 2 years ago
<a href="https:&#x2F;&#x2F;mijn.overheid.nl&#x2F;security.txt" rel="nofollow">https:&#x2F;&#x2F;mijn.overheid.nl&#x2F;security.txt</a><p>404<p>but this one does exist <a href="https:&#x2F;&#x2F;www.ncsc.nl&#x2F;.well-known&#x2F;security.txt" rel="nofollow">https:&#x2F;&#x2F;www.ncsc.nl&#x2F;.well-known&#x2F;security.txt</a>
评论 #36149247 未加载
logifailalmost 2 years ago
Unless there&#x27;s a way to mandate that the security team&#x27;s contacts listed in security.txt actually respond in a timely manner to security-related messages that are sent to them, then I have a nagging feeling that:<p>* well-run organizations won&#x27;t benefit from doing this, since their security teams were already easy to reach<p>and<p>* poorly-run organizations won&#x27;t become any better <i>by</i> doing this, because one text file doesn&#x27;t fix a broken org
qawwadsalmost 2 years ago
1. Find a vulnerability<p>2. Contact the website maintainer to report it<p>3. Get swatted, harrassed by cops, sued, and jailed over it.<p>No thank.
fareeshalmost 2 years ago
Seems like a vector for phishing &#x2F; social engineering and scammers &#x2F; advertisers
评论 #36149753 未加载
liotieralmost 2 years ago
Isn&#x27;t this what Whois is for ?
jruohonenalmost 2 years ago
I hope other countries follow!
评论 #36149081 未加载