3 ms·
False dichotomy. Yes, you can broadly split people who find vulnerabilities into those who want to use or sell them, and those who want to get them fixed. And
by wnoise 2y ago
False dichotomy. Yes, you can broadly split people who find vulnerabilities into those who want to use or sell them, and those who want to get them fixed. And those who want to use or sell them will never tell the victim.
But those who notice a problem do have some point of aggravation past which they'll just go "I can't be bothered; fuck 'em". You really do want to make it as easy as possible for them to report. (And alsp make it seem as safe as possible; having a reputation for suing reporters is also terrible.)
Now, in practice, I don't thing security.txt is a particularly useful way of doing this, but it is pretty easy to add.
- tptacek 2y agoNobody is selling vulnerabilities that would otherwise be reported by looking something up in a "security.txt".