76% of 623 EU software vendors have no security.txt ahead of the CRA 24h rule

15 pointsposted 8 hours ago
by gilsha

6 Comments

michaelt

7 hours ago

Those of you who publish a security.txt - how many reports do you get, and what's the typical quality level?

If I push to add one to my employer's website, will our security team thank me for doing so?

sudorm-rf--no-p

6 hours ago

Recently I let claude write a script to export some data from a website. While testing the script I came across a bug that leaked the e-mail address of other users, potentially also more data related to the session. Upon discovery Claude did recommend to check for a security.txt, but none was available. Sent a mail to their support instead. A security.txt with further instructions and maybe a PGP key would have been nice…