fosstodon.org is one of the many independent Mastodon servers you can use to participate in the fediverse.
Fosstodon is an invite only Mastodon instance that is open to those who are interested in technology; particularly free & open source software. If you wish to join, contact us for an invite.

Administered by:

Server stats:

8.6K
active users

#securitytxt

0 posts0 participants0 posts today
Habr<p>Как рассказать о сайте поисковой системе 2</p><p>Доброго времени суток. В этой статье я хочу дополнить первую часть рассказа о том как же донести поисковику информацию о своём сайте. Здесь будут рассмотрены такие темы как IndexNow, security.txt, schema.org.</p><p><a href="https://habr.com/ru/articles/901490/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">habr.com/ru/articles/901490/</span><span class="invisible"></span></a></p><p><a href="https://zhub.link/tags/seo%D0%BE%D0%BF%D1%82%D0%B8%D0%BC%D0%B8%D0%B7%D0%B0%D1%86%D0%B8%D1%8F" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>seoоптимизация</span></a> <a href="https://zhub.link/tags/schemaorg" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>schemaorg</span></a> <a href="https://zhub.link/tags/indexnow" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>indexnow</span></a> <a href="https://zhub.link/tags/securitytxt" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>securitytxt</span></a></p>
J👀<p>I just noticed that the <a href="https://mastodon.n41.lat/tags/securitytxt" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>securitytxt</span></a> file in the <a href="https://mastodon.n41.lat/tags/Atlassian" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Atlassian</span></a> Website expired several months ago 🤦 </p><p><a href="https://www.atlassian.com/.well-known/security.txt" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">atlassian.com/.well-known/secu</span><span class="invisible">rity.txt</span></a></p>

Als ethische hackers een beveiligingslek vinden in je bedrijfsnetwerk, dan wil je dat meteen weten. Bij wie kunnen ze dit melden?

Daarvoor is security.txt: een eenvoudig tekstbestand op je webserver met de contactgegevens van jouw IT-verantwoordelijke.

Inmiddels is er ook een security.txt WordPress-plugin beschikbaar gesteld voor eindgebruikers en registrars.

Meer over security.txt ⤵️

digitaltrustcenter.nl/security

Meer over de WordPress-plugin ⤵️

verenigingvanregistrars.nl/nie

Friends of #InfoSec I would like for some help! I would like to see your security.txt’s!

I am working with a lot of really small companies that will benefit from a good security.txt and if any group of people has good ones I know its gonna be here!

I already use and share securitytxt.org/ as well as the RFC rfc-editor.org/rfc/rfc9116

If you are a PenTester/Researcher, you should get a say too! What do you want in a security.txt file? What other updates should small orgs be adding to help you help us?

security.txtsecurity.txtA proposed standard that allows websites to define security policies.

Herken je dit? Je meldt een probleem, maar wordt van het kastje naar de muur gestuurd. Beveiligingsonderzoekers en ethisch hackers ervaren dit dagelijks. Gelukkig is er een oplossing: security.txt!

Security.txt zorgt ervoor dat beveiligingsmeldingen altijd bij de juiste persoon terechtkomen. Wil je weten hoe je jouw website hiermee beter kunt beschermen? Lees ons nieuwste blog op bit.nl

bit.nl/news/3560/293/Waarom-ie

www.bit.nlWaarom iedere website een security.txt nodig heeftHerken je dat? Je merkt ergens een probleem op, maar jij kan dat niet oplossen. Maar je kan wel iemand attenderen op dat probleem, zodat die persoon of...

As a maintainer of open-source software, I want to provide ways to disclose vulnerabilities. I already have a SECURITY.md in all my repositories on GitHub. There is a copy of it on my website (cj.rs/open-source/docs/securit), because why website hosts homepages for my projects.

Today, I’ve added a security.txt file (securitytxt.org/) in the standard location: cj.rs/.well-known/security.txt

cj.rs · Security PolicyGuidelines to report a security issue

Security.txt is een eenvoudig tekstbestand waarin organisaties hun 'responsible disclosure’-beleid en contactpersonen kunnen publiceren.

De toepassing van #securitytxt wordt waarschijnlijk vanaf de eerste helft van volgend jaar toegevoegd aan de Registrar Scorecard (RSC). Dat betekent dat er dan een financiële korting wordt geven op domeinnamen waarvan de website een geldig en bruikbaar security.txt-bestand aanbiedt.

Meer informatie ⤵️

digitaltrustcenter.nl/nieuws/s

Does anyone know how to reach a human at #NextDNS? I'm a paying customer, but I'm unable to sign up for their support forums due to an error (yes, they require a *second* login). They also don't have a "security.txt" file that I can use.

They're blocking my domain to tell me they're not blocking my domain. Literally. I've reset all my #DNS caches and even slept for eight hours, to no avail.

I restored to emailing the owner of the company through the email address on his GitHub profile. It's that mis-managed over there. I think I want my money back.

(Note: I changed Firefox to use Cloudflare's DoH to post this.)

Je ne trouve pas un seul #média français, grand ou petit, qui ait un moyen de contact spécifique pour signaler les problèmes de sécurité informatique sur leur site web (ni /.well-known/security.txt[1] ni mention sur la page ou le formulaire de contact). Rarement, il y a une option « problème technique » dans le formulaire, mais rien de plus spécifique.

@davduf @reflets @mediapart @blast_info @bastamedia @LeMediaTV @lesjoursfr @mdiplo @lemonde

[1] securitytxt.org/
Exemple : nytimes.com/.well-known/securi

security.txtsecurity.txtA proposed standard that allows websites to define security policies.

Are you #CISO, #ISO or simply responsible for IT security in your company? We want to hear from you!

We have reported hundreds of #vulnerabilities to individuals, companies and other organisations over the past few days.

Often we can't find a direct contact on the website. Sending an email to info@example.com tends to send our mail into the ether and we never hear from the company again.

When we inquire about particularly critical cases, we often hear: "Oh, we didn't see that email". 🤦‍♂️

Unfortunately, many companies do not have a "single point of contact" such as a security.txt or bug bounty programme.

Hence our question to you: How would you like us to report vulnerabilities to you?