3 ms·
At one point in time I believe there was also a discussion on why somebody was removing it from their site. I'm having a hard time finding it currently and reme
by blue_shirt 7y ago
At one point in time I believe there was also a discussion on why somebody was removing it from their site. I'm having a hard time finding it currently and remember it being for excessive contacts from people using automated tools to scan their site.
Edit: Found it, https://news.ycombinator.com/item?id=19152145 https://news.ycombinator.com/item?id=19152145
- DyslexicAtheist 7y agothere is a draft (from November 27, 2019) that makes the presence of a disclosure policy (using security.txt) mandatory on gov domains: "Binding Operational Directive 20-01 Develop and Publish a Vulnerability Disclosure Policy" https://cyber.dhs.gov/bod/20-01/ https://cyber.dhs.gov/bod/20-01/ > Create a security.txt15 file at the “/.well-known/” path16 of the agency’s primary .gov domain. This file must include the Policy and Contact fields, as specified in the Internet-Draft.17