#SecurityTxt

Jiri Grönroosjirigronroos
2025-10-25

How do organizations instruct using ? Many organizations, such as CISA, and the French government, endorse the use of security.txt.

❌ = Not available
❕ = Available but flaws
✅ = Available and conforms

dvv.fi: ❌
eduskunta.fi: ❌
elisa.fi: ❕Missing date (RFC violation)
hel.fi: ❌
op.fi: ❌
puolustusvoimat.fi: ❌
kanta.fi: ❕Date against recommendation
suomi.fi: ❌
traficom.fi: ✅
yle.fi: ❕Date against recommendation

2025-10-17

you had one job #securitytxt

2025-08-26

Artikel zu #securitytxt in DuD veröffentlicht: Der Artikel "RFC 9116 (“security.txt”) an deutschen Hochschulservern" von Finn Eckstein, Ria Rosenauer, Pascal Huppert, Melanie Volkamer und Dominik Herrmann wurde diesen Monat in der Zeitschrift #Datenschutz und #Datensicherheit veröffentlicht. In dem Artikel wird die Verbereitung des Standards RFC 9116 an deutschen Hochschulen untersucht. Mit der Umsetzung des Standards können die Betreiber von Websites Kontaktdaten für die Meldung von Sicherheitslücken bereitstellen. Durch Benachrichtigung der Hochschulen, die keine security.txt implementiert haben, hatte sich die Bereitstellung zwar verdreifacht, allerdings auf sehr niedrigem Niveau. Die Form der Ansprache hatte dabei keinen Effekt auf die Implementierung: link.springer.com/article/10.1
@herdom

2025-04-17

Как рассказать о сайте поисковой системе 2

Доброго времени суток. В этой статье я хочу дополнить первую часть рассказа о том как же донести поисковику информацию о своём сайте. Здесь будут рассмотрены такие темы как IndexNow, security.txt, schema.org.

habr.com/ru/articles/901490/

#seoоптимизация #schemaorg #indexnow #securitytxt

PPC Landppcland
2024-12-24

Cloudflare launches free Security.txt generator to boost website security: New tool simplifies vulnerability disclosure process, aligning with industry standards for enhanced web security practices. ppc.land/cloudflare-launches-f

2024-11-15

I just noticed that the #securitytxt file in the #Atlassian Website expired several months ago 🤦

atlassian.com/.well-known/secu

2024-11-11

#Cloudflare Advocates for Broader Adoption of #securitytxt Standard for Vulnerability Reporting

infoq.com/news/2024/11/cloudfl

2024-09-25

Als ethische hackers een beveiligingslek vinden in je bedrijfsnetwerk, dan wil je dat meteen weten. Bij wie kunnen ze dit melden?

Daarvoor is security.txt: een eenvoudig tekstbestand op je webserver met de contactgegevens van jouw IT-verantwoordelijke.

Inmiddels is er ook een security.txt WordPress-plugin beschikbaar gesteld voor eindgebruikers en registrars.

Meer over security.txt ⤵️

digitaltrustcenter.nl/security

Meer over de WordPress-plugin ⤵️

verenigingvanregistrars.nl/nie

#securitytxt #rd #cvd

2024-08-23

Friends of #InfoSec I would like for some help! I would like to see your security.txt’s!

I am working with a lot of really small companies that will benefit from a good security.txt and if any group of people has good ones I know its gonna be here!

I already use and share securitytxt.org/ as well as the RFC rfc-editor.org/rfc/rfc9116

If you are a PenTester/Researcher, you should get a say too! What do you want in a security.txt file? What other updates should small orgs be adding to help you help us?

#securitytxt #RFC9116

2024-06-18

Herken je dit? Je meldt een probleem, maar wordt van het kastje naar de muur gestuurd. Beveiligingsonderzoekers en ethisch hackers ervaren dit dagelijks. Gelukkig is er een oplossing: security.txt!

Security.txt zorgt ervoor dat beveiligingsmeldingen altijd bij de juiste persoon terechtkomen. Wil je weten hoe je jouw website hiermee beter kunt beschermen? Lees ons nieuwste blog op bit.nl

bit.nl/news/3560/293/Waarom-ie

#Cybersecurity #SecurityTXT #InternetVeiligheid #BIT #ModerneInternetStandaarden

Colin Cogle :verified:colin@colincogle.name
2024-04-14

@neil Yes, as anyone should! I’ve written about it, convinced a vendor to create one, and even made a #PowerShell module to fetch and parse them: github.com/rhymeswithmogul/Sec #SecurityTxt

Clément Joly MOVEDcjoly@fosstodon.org
2024-03-15

As a maintainer of open-source software, I want to provide ways to disclose vulnerabilities. I already have a SECURITY.md in all my repositories on GitHub. There is a copy of it on my website (cj.rs/open-source/docs/securit), because why website hosts homepages for my projects.

Today, I’ve added a security.txt file (securitytxt.org/) in the standard location: cj.rs/.well-known/security.txt

#RFC9116 #securitytxt

2024-03-14

Security.txt is een eenvoudig tekstbestand waarin organisaties hun 'responsible disclosure’-beleid en contactpersonen kunnen publiceren.

De toepassing van #securitytxt wordt waarschijnlijk vanaf de eerste helft van volgend jaar toegevoegd aan de Registrar Scorecard (RSC). Dat betekent dat er dan een financiële korting wordt geven op domeinnamen waarvan de website een geldig en bruikbaar security.txt-bestand aanbiedt.

Meer informatie ⤵️

digitaltrustcenter.nl/nieuws/s

Colin Cogle :verified:colin@colincogle.name
2024-03-05

Does anyone know how to reach a human at #NextDNS? I'm a paying customer, but I'm unable to sign up for their support forums due to an error (yes, they require a *second* login). They also don't have a "security.txt" file that I can use.

They're blocking my domain to tell me they're not blocking my domain. Literally. I've reset all my #DNS caches and even slept for eight hours, to no avail.

I restored to emailing the owner of the company through the email address on his GitHub profile. It's that mis-managed over there. I think I want my money back.

(Note: I changed Firefox to use Cloudflare's DoH to post this.)

#securitytxt #bugreports #softwaredevelopment #itsalwaysdns #support

A NextDNS block page that says, "Great, colincogle.name is not blocked anymore. Smiley face. Clear your local DNS cache to access this website now, or wait a few minutes."  The irony is that doing any of those things doesn't get you to the site.
Ciourte Piailleciourte@piaille.fr
2024-02-23

Je ne trouve pas un seul #média français, grand ou petit, qui ait un moyen de contact spécifique pour signaler les problèmes de sécurité informatique sur leur site web (ni /.well-known/security.txt[1] ni mention sur la page ou le formulaire de contact). Rarement, il y a une option « problème technique » dans le formulaire, mais rien de plus spécifique.

@davduf @reflets @mediapart @blast_info @bastamedia @LeMediaTV @lesjoursfr @mdiplo @lemonde

[1] securitytxt.org/
Exemple : nytimes.com/.well-known/securi

#sécurité_informatique #sécuritéInformatique #securityTxt

2024-02-02

@freddy hopefully @mozilla also got a #SecurityTXT file on their site and provides Pubkeys to communicate securely...

securitytxt.org/

PS: "Typical Working Hours" is undefined unless you state them and the applicable timezone...

Some people like myself are nocturnal...

social.security.plumbing/@fred

2024-01-18

Ein erster Hinweis darauf, ob ein Unternehmen, eine Institution, ein Websitebetreiber etc. an Responsible Disclosure interessiert ist, ist eine security.txt. Meist zu finden unter /security.txt oder /.well-known/security.txt. 👇

securitytxt.org/

#security #sicherheit #hacking #hacker #responsibledisclosure #securitytxt

Bart Groeneveldbartavi@mastodon.nl
2024-01-04

If you ever want to quickly scan your security.txt, you can use the sectxt python library: github.com/DigitalTrustCenter/

#securitytxt

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst