| ▲ | 76% of 623 EU software vendors have no security.txt ahead of the CRA 24h rule(cradrill.com) | |||||||
| 14 points by gilsha 3 hours ago | 6 comments | ||||||||
| ▲ | michaelt 2 hours ago | parent | next [-] | |||||||
Those of you who publish a security.txt - how many reports do you get, and what's the typical quality level? If I push to add one to my employer's website, will our security team thank me for doing so? | ||||||||
| ▲ | sudorm-rf--no-p an hour ago | parent | prev | next [-] | |||||||
Recently I let claude write a script to export some data from a website. While testing the script I came across a bug that leaked the e-mail address of other users, potentially also more data related to the session. Upon discovery Claude did recommend to check for a security.txt, but none was available. Sent a mail to their support instead. A security.txt with further instructions and maybe a PGP key would have been nice… | ||||||||
| ▲ | reconnecting 2 hours ago | parent | prev | next [-] | |||||||
What is the difference? | ||||||||
| ||||||||
| ▲ | toomuchtodo 3 hours ago | parent | prev | next [-] | |||||||
For those on Cloudflare, it's a toggle to enable this and provide the necessary values. https://developers.cloudflare.com/security-center/infrastruc... | ||||||||
| ▲ | gilsha 3 hours ago | parent | prev [-] | |||||||
[flagged] | ||||||||