TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Security.txt file now mandatory for Dutch government websites

359 点作者 pseudotrash将近 2 年前

24 条评论

mtmail将近 2 年前
&gt; The aim is that, for example, ethical hackers can immediately contact the right person or department to tackle the vulnerability.<p>We added such a file years ago. There&#x27;s still some security researchers (&quot;bug hunters&quot;) not aware of the standard and email other email addresses (info@, invoice@, data-protection@). Nobody has ever used the GPG key we list in the security.txt file. The email address we list (security@) hasn&#x27;t received any significant spam.
评论 #36149830 未加载
评论 #36149649 未加载
评论 #36149443 未加载
评论 #36149863 未加载
aequitas将近 2 年前
To get an idea of how well our government organisations get along with implementing this (and a lot of other basic security requirements, like TLS, IPv6, DNSSEC, etc) you can view these maps[0][1].<p>We maintain a set of open source tools to easily get you started[2]. If you would like help to have this for your country&#x2F;government&#x2F;organisation as well, feel free to contact us.<p>[0] <a href="https:&#x2F;&#x2F;basisbeveiliging.nl&#x2F;#&#x2F;metric-progress&#x2F;NL&#x2F;municipality&#x2F;internet_nl_wsm_web_appsecpriv_securitytxt" rel="nofollow">https:&#x2F;&#x2F;basisbeveiliging.nl&#x2F;#&#x2F;metric-progress&#x2F;NL&#x2F;municipalit...</a> [1] <a href="https:&#x2F;&#x2F;basisbeveiliging.nl&#x2F;#&#x2F;maps" rel="nofollow">https:&#x2F;&#x2F;basisbeveiliging.nl&#x2F;#&#x2F;maps</a> [2] <a href="https:&#x2F;&#x2F;gitlab.com&#x2F;internet-cleanup-foundation&#x2F;web-security-map" rel="nofollow">https:&#x2F;&#x2F;gitlab.com&#x2F;internet-cleanup-foundation&#x2F;web-security-...</a>
评论 #36150682 未加载
评论 #36151238 未加载
评论 #36153153 未加载
oefrha将近 2 年前
This has been discussed to death every time security.txt comes up, but in my experience it&#x27;s been a great way to receive spam about bullshit &quot;vulnerabilities&quot; from low effort scanners operated by &quot;security researchers&quot;.<p>Much like how people publish email addresses online using human readable replacements (e.g. AT instead of @) to avoid spam, I&#x27;d rather put up a contact page that&#x27;s easy for humans to find but nontrivial to automate.
评论 #36149284 未加载
NoZebra120vClip将近 2 年前
<p><pre><code> 2.5.6. Hiring The &quot;Hiring&quot; field is used for linking to the vendor&#x27;s security-related job positions. If this field indicates a web URI, then it MUST begin with &quot;https:&#x2F;&#x2F;&quot; (as per Section 2.7.2 of [RFC7230]). </code></pre> Hey, I just found a new way to job hunt!
评论 #36149317 未加载
评论 #36149549 未加载
评论 #36149834 未加载
throwawaaarrgh将近 2 年前
Keep in mind this is only mandatory <i>for government websites</i>. That&#x27;s a pretty low bar. If I worked for the government, or even a company that had one clear way to contact security, I would love this. I honestly have no fucking idea how to directly contact security most of the time and that&#x27;s insane because I actually want to help them.<p>I don&#x27;t care if they receive spam, I just want them to tell me how to contact them. Give me a captcha form, a phone number, an AOL Instant Messenger handle, I don&#x27;t care.
评论 #36149704 未加载
a2800276将近 2 年前
&quot;Dutch government websites must comply with the security.txt standard from 25 May. This is announced by the Digital Trust Center of the National Government.&quot;<p>Somewhat ironically:<p><a href="https:&#x2F;&#x2F;www.digitaltrustcenter.nl&#x2F;security.txt" rel="nofollow">https:&#x2F;&#x2F;www.digitaltrustcenter.nl&#x2F;security.txt</a><p>The website of the Digital Trust Center returns 404
评论 #36150201 未加载
评论 #36150196 未加载
评论 #36150190 未加载
androidas将近 2 年前
Really cool. I’ve done responsible disclosure in the past and finding someone who’ll listen is probably the hardest part of it
评论 #36149094 未加载
评论 #36150415 未加载
hoofhearted将近 2 年前
I’m working on a simple website generator for developers and content creators.<p>I’ve already included everything a user would want for a complete website, including a robots.txt, sitemaps, perfect Lighthouse seo score, rich snippets, and a ton of other stuff.<p>Should I consider adding an auto generated security.txt file along side the robots.txt file for users?<p>Do you’all think a security.txt file is something users would want in 2023? Or would it look stupid and confusing?<p><a href="https:&#x2F;&#x2F;github.com&#x2F;elegantframework&#x2F;elegant-cli">https:&#x2F;&#x2F;github.com&#x2F;elegantframework&#x2F;elegant-cli</a>
评论 #36152473 未加载
评论 #36151419 未加载
serial_dev将近 2 年前
Never heard about security txt files until now, but it makes a lot of sense!<p>Regulations are a hit or miss (e.g the cookie notification rules have some good parts but I wonder if there isn&#x27;t any room for improvement in the current &quot;visiting a website for 10 seconds and clicking whatever the big button is so that I see the content in interested in&quot; status quo.<p>This one is not obtrusive, easy to implement (though only developers care about this part) and solves the problem.
评论 #36149490 未加载
评论 #36149801 未加载
评论 #36149230 未加载
punnerud将近 2 年前
I checked the top 20 most used websites in Germany (with .de), and number 20 on the list is the first to have it: <a href="https:&#x2F;&#x2F;www.focus.de&#x2F;security.txt" rel="nofollow">https:&#x2F;&#x2F;www.focus.de&#x2F;security.txt</a><p>Most used webpages: <a href="https:&#x2F;&#x2F;www.similarweb.com&#x2F;top-websites&#x2F;germany&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.similarweb.com&#x2F;top-websites&#x2F;germany&#x2F;</a>
评论 #36150065 未加载
plugin-baby将近 2 年前
Should the title be “security.txt” instead of “Security.txt”?
评论 #36149208 未加载
jwilk将近 2 年前
security.txt discussed on HN:<p>2017: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=15416198" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=15416198</a> (145 comments)<p>2019: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=19151213" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=19151213</a> (55 comments)<p>2021: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=26455493" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=26455493</a> (167 comments)
milliams将近 2 年前
I&#x27;ve just checked the UK&#x27;s GDS advice and they have it as a &quot;should&quot;: <a href="https:&#x2F;&#x2F;gds-way.cloudapps.digital&#x2F;manuals&#x2F;security-overview-for-websites.html#10-implement-security-txt" rel="nofollow">https:&#x2F;&#x2F;gds-way.cloudapps.digital&#x2F;manuals&#x2F;security-overview-...</a><p>They have more information at <a href="https:&#x2F;&#x2F;gds-way.cloudapps.digital&#x2F;standards&#x2F;vulnerability-disclosure.html" rel="nofollow">https:&#x2F;&#x2F;gds-way.cloudapps.digital&#x2F;standards&#x2F;vulnerability-di...</a> where they strengthen the advice by saving:<p><pre><code> As per the current policy, we only accept reports from services that have a security.txt file pointing to the security policy.</code></pre>
评论 #36149212 未加载
评论 #36150047 未加载
JohnFen将近 2 年前
Whatever happened to just having the standard &quot;abuse@domain.name&quot; email address?
baknu将近 2 年前
The formal news release on this from the Dutch Standardization Forum can be found here: <a href="https:&#x2F;&#x2F;forumstandaardisatie.nl&#x2F;nieuws&#x2F;securitytxt-mandatory-dutch-government" rel="nofollow">https:&#x2F;&#x2F;forumstandaardisatie.nl&#x2F;nieuws&#x2F;securitytxt-mandatory...</a><p>Note that you can test if a website has valid security.txt with the Internet.nl test tool: <a href="https:&#x2F;&#x2F;en.internet.nl&#x2F;article&#x2F;securitytxt-test-toegevoegd&#x2F;" rel="nofollow">https:&#x2F;&#x2F;en.internet.nl&#x2F;article&#x2F;securitytxt-test-toegevoegd&#x2F;</a>
benatkin将近 2 年前
This is a win for GPG. Some, like the current PyPI maintainers, want to throw it out with no replacement. That&#x27;s a terrible idea. And I don&#x27;t see why it needs to be replaced completely.
qwertox将近 2 年前
<a href="https:&#x2F;&#x2F;www.amsterdam.nl&#x2F;security.txt" rel="nofollow">https:&#x2F;&#x2F;www.amsterdam.nl&#x2F;security.txt</a> returns<p>---<p>Contact: <a href="https:&#x2F;&#x2F;www.amsterdam.nl&#x2F;privacy&#x2F;informatiebeveiliging-gemeente-amsterdam&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.amsterdam.nl&#x2F;privacy&#x2F;informatiebeveiliging-gemee...</a><p>Expires: 2024-02-01T10:00:00.000Z<p>Acknowledgments: <a href="https:&#x2F;&#x2F;www.informatiebeveiligingsdienst.nl&#x2F;?s=hall+of+fame" rel="nofollow">https:&#x2F;&#x2F;www.informatiebeveiligingsdienst.nl&#x2F;?s=hall+of+fame</a><p>Preferred-Languages: en,nl<p>---<p>rfc9116<p>2.5.1. Acknowledgments<p>The &quot;Acknowledgments&quot; field indicates a link to a page where security researchers are recognized for their reports. The page being referenced should list security researchers that reported security vulnerabilities and collaborated to remediate them. Organizations should be careful to limit the vulnerability information being published in order to prevent future attacks.<p>If this field indicates a web URI, then it MUST begin with &quot;<a href="https:&#x2F;&#x2F;" rel="nofollow">https:&#x2F;&#x2F;</a>&quot; (as per Section 2.7.2 of [RFC7230]).
foxbyte将近 2 年前
Really appreciated this article - it&#x27;s high time the Dutch government websites took steps like these towards strengthening their security! Still, they could definitely do with a bit more user-friendly explanations, so everyone can understand the importance of initiatives like security.txt.
yread将近 2 年前
<a href="https:&#x2F;&#x2F;mijn.overheid.nl&#x2F;security.txt" rel="nofollow">https:&#x2F;&#x2F;mijn.overheid.nl&#x2F;security.txt</a><p>404<p>but this one does exist <a href="https:&#x2F;&#x2F;www.ncsc.nl&#x2F;.well-known&#x2F;security.txt" rel="nofollow">https:&#x2F;&#x2F;www.ncsc.nl&#x2F;.well-known&#x2F;security.txt</a>
评论 #36149247 未加载
logifail将近 2 年前
Unless there&#x27;s a way to mandate that the security team&#x27;s contacts listed in security.txt actually respond in a timely manner to security-related messages that are sent to them, then I have a nagging feeling that:<p>* well-run organizations won&#x27;t benefit from doing this, since their security teams were already easy to reach<p>and<p>* poorly-run organizations won&#x27;t become any better <i>by</i> doing this, because one text file doesn&#x27;t fix a broken org
qawwads将近 2 年前
1. Find a vulnerability<p>2. Contact the website maintainer to report it<p>3. Get swatted, harrassed by cops, sued, and jailed over it.<p>No thank.
fareesh将近 2 年前
Seems like a vector for phishing &#x2F; social engineering and scammers &#x2F; advertisers
评论 #36149753 未加载
liotier将近 2 年前
Isn&#x27;t this what Whois is for ?
jruohonen将近 2 年前
I hope other countries follow!
评论 #36149081 未加载