TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Does Your Organization Have a Security.txt File?

13 点作者 parsecs超过 3 年前

2 条评论

themodelplumber超过 3 年前
&gt; It seems that setting up a security.txt file tends to invite a rather high volume of spam. Most of these junk emails come from self-appointed penetration testers who — without any invitation to do so — run automated vulnerability discovery tools and then submit the resulting reports in hopes of securing a consulting engagement or a bug bounty fee.<p>Yep, I have a friend who just set hers up; she said within days she had received several emails that seemed more like threats than disclosures or offers to disclose. Worse yet, maybe for all parties, the wording was on the &quot;way too diplomatic&quot; side and this led to a loss of trust.<p>Prior to this situation she said her favorite reports involved <a href="https:&#x2F;&#x2F;www.openbugbounty.org&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.openbugbounty.org&#x2F;</a> and friendly advice on how to resolve the issue.
fspacef超过 3 年前
My security is government tier.