securitytxt.org
solo1
Our great sponsors
securitytxt.org | solo1 | |
---|---|---|
42 | 56 | |
60 | 2,260 | |
- | 0.0% | |
4.2 | 0.0 | |
20 days ago | over 1 year ago | |
HTML | C | |
MIT License | GNU General Public License v3.0 or later |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
securitytxt.org
-
How to respond to unsolicited vulnerability report from users of public sites?
You might consider setting up security.txt notifications, per RFC 9116, to funnel people into the right notification paths. Otherwise, they might try spamming random emails they find or can guess at. I've had external researchers contact our CTO and CEO directly, creating a new problem for me.
-
How to make a bounty bug request
Check if they have a security.txt, if they do not, check their /security. If both come up empty, use any contact form that they have available.
- A qui dénoncer une brèche?
-
Anywhere I can advertise a bounty for my site?
In addition to the Bug bounty programs already posted in the comments, I'd suggest you create a security.txt with a dedicated security contact.
-
need advice please
Does the website have a responsible disclosure page or a security.txt?
-
Whats the policy on posting open government or international government directories?
there's technically https://securitytxt.org as well; but sadly it's not in super duper wide deployment (some big places have it, though!)
-
Implementation of RFC 9116 (security.txt) as well as possibility for encrypted contact
Especially in the area you guys are operating in, I think it would be great if you could implement RFC 9116 (https://securitytxt.org/). If someone finds a vulnerability on your website, the client or even the SPN, this would make communication or a responsible disclosure process much easier. Furthermore, it would be great if the possibility for secure communication with your staff (e.g. using GPG) would be possible.
- I found a security issue on a website, came on a different sub to ask how to monetise this, gave the owners one week to give me a job, then when they didn't, made a tiktok about it to say how knowledgeable in IT I am. Why are they threatening me?
-
Infosys leaked FullAdminAccess AWS keys on PyPI for over a year
When do companies finally start adopting the `security.txt` proposal (see https://securitytxt.org).
Would have made a big difference!
- security.txt
solo1
- Thetis, Yubikey, Solokey, Nitrokey, Onlykey, etc. Differences and Compatability?
- Yubico is merging with ACQ Bure and intends to go public
-
alternative to yubikey with requirements?
Try Solokeys https://solokeys.com v2 is open source USB-C and NFC compatible work with FIDO and web Auth.
- How to Yubikey: A Configuration Cheatsheet
- GitHub Mandates 2FA for All Developers
- The Blue Is Gone
-
On using bitwarden for TOTP:
Also take a look at solokeys. They are very affordable and support FIDO2 and FIDO U2F -- meaning they have overlapping protocols with Bitwarden, and they certainly work on Google.
-
Wanting to setup a luks USB key system
Try This
-
Sign in with Google has been removed for your privacy
You might want to check out https://solokeys.com/ then. They're pretty new (shipping for about a year) but they do full FOSS firmware & software as well as most hardware being FOSS as well.
-
Security keys opinion
yubikey is always recommend but solokey is open source
What are some alternatives?
security.txt
YubiKey-Guide - Guide to using YubiKey for GnuPG and SSH
countwords - Playing with counting word frequencies (and performance) in various languages.
KeePass2.x - unofficial mirror of KeePass2.x source code
hipaa-compliance-developers-guide - A developers guide to HIPAA compliance and application development.
mortar - Framework to join Linux's physical security bricks.
irssi - The client of the future
trezor-hardware - :wrench: Hardware design of Trezor
password-manager-resources - A place for creators and users of password managers to collaborate on resources to make password management better.
OpenSK - OpenSK is an open-source implementation for security keys written in Rust that supports both FIDO U2F and FIDO2 standards.
wyhash - The FASTEST QUALITY hash function, random number generators (PRNG) and hash map.
nrf52-u2f - An Open-Source FIDO U2F implementation on nRF52 SoC