3 ms·
Seems like a reasonably good idea. More of a question about RFC’s than the spec itself. I noticed while reading the RFC it mentions this: > By convention, the
by pseudoramble 6y ago
Seems like a reasonably good idea. More of a question about RFC’s than the spec itself. I noticed while reading the RFC it mentions this:
> By convention, the file is named "security.txt".
Isn’t the point of the RFC so that it wouldn’t be by convention anymore? Or are they saying the idea for the name was from prior conventions? Or maybe I’m just reading into it too much and it doesn’t really matter.
- anamexis 6y agoI think the latter - they are saying the idea for the name was from prior conventions. Section 4 spells it out explicitly: > For web-based services, organizations MUST place the security.txt file under the "/.well-known/" path;
- willeh 6y agoI agree, it definitely seems that the phrasing there needs work. Overall I would say most RFCs are well substandard especially when compared to ISO standards which tend to be extremely precise. That being said, interoperability within tech is amazing so perhaps there is something to be said about the idea of loose standards and working code after all.