StrausFuenf - Lemmy
  • Communities
  • Multi-communities
  • Support Lemmy
  • Search
  • Login
Selfhosted@lemmy.worldbynawan@scribe.disroot.org
2 days

For those selfhosting stuff that's publicy accessible, do you serve a security.txt?

English

https://en.wikipedia.org/wiki/Security.txt

Reposted from r/selfhosted.

14
    You must log in or register to comment.

    • ahmedezat_katteb@lemmy.worldEnglish
      19 hours

      I do, but with a few tweaks that cut most of the junk the other comments mention:

      • Point Contact: at a dedicated alias, not your main inbox, and filter it hard. If the noise gets bad you can drop the alias without touching anything else.
      • Add a Policy: line linking to a short page that says plainly there is no bug bounty and no payment for reports. Most beg-bounty mails are mass-sent with a payment ask, so this gives you something to point them at and lets you bin them without guilt.
      • Don’t forget Expires:, it’s actually required by RFC 9116 and a lot of hand-written files leave it out. Set a calendar reminder to bump it.
      • Serve it at /.well-known/security.txt; the root path is only a legacy fallback.

      Whether it’s worth it for a homelab is debatable, but if you host anything other people rely on (a Matrix/Lemmy instance, a shared Nextcloud), having one real contact path beats someone finding a hole and having nowhere to send it.

      • slazer2au@lemmy.worldEnglish
        2 days

        No, because it invites beg bounties and slop reports.

          • Synestine@sh.itjust.worksEnglish
            1 day

            If you run any sort of public facing website, you’ll likely get some of those eventually.

          • lambalicious@lemmy.sdf.orgEnglish
            2 days

            No, it’s free real estate for scams, slop and the like.

            • Oha@lemmy.pobierz.net
              2 days

              Yes, but I should probably also put one up on my other domains

                • Hal@piefed.nzEnglish
                  1 day

                  I was gonna say you had it in the wrong place, but it looks like you also serve it in the /.well-known/ location as well.

                  • B0rax@feddit.orgEnglish
                    2 days

                    Nice domain!

                      • Oha@lemmy.pobierz.netEnglish
                        13 hours

                        thanks!

                        • officermike@lemmy.worldEnglish
                          2 days

                          American Psycho business card gif

                      • majster@lemmy.zipEnglish
                        1 day

                        Do people actually contact you with that?

                          • moldy_rice@piefed.keyboardvagabond.comEnglish
                            21 hours

                            Yep. Looots of phishing emails.

                            • 3abas@lemmy.worldEnglish
                              1 day

                              I have a security.txt with an email to report vulnerabilities and a public key to encrypt sensitive information. The only reports I ever got were on the contract us form, unencrypted.

                            • xyro@morbier.fooEnglish
                              2 days

                              Nope, maybe I should ! Thanks for the reminder !

                              • motruck@lemmy.zipEnglish
                                2 days

                                Why so people ignore that too?

                                Selfhosted@lemmy.world

                                selfhosted@lemmy.world

                                Subscribe from remote instance

                                Create post

                                Report community

                                Modlog
                                You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !selfhosted@lemmy.world

                                A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don’t control.

                                Rules:

                                Detailed Rules Post

                                1. Be civil.

                                2. No spam.

                                3. Posts are to be related to self-hosting.

                                4. Don’t duplicate the full text of your blog or readme if you’re providing a link.

                                5. Submission headline should match the article title.

                                6. No trolling.

                                7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

                                8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

                                Resources:

                                • selfh.st Newsletter and index of selfhosted software and apps
                                • awesome-selfhosted software
                                • awesome-sysadmin resources
                                • Self-Hosted Podcast from Jupiter Broadcasting

                                Any issues on the community? Report it using the report flag.

                                Questions? DM the mods!

                                Visibility: Public

                                This community is visible to everyone.

                                • 355 users / Day
                                • 2.42K users / Week
                                • 5.11K users / Month
                                • 14.1K users / 6 months
                                • 1.66K posts
                                • 31.2K comments
                                • 1 local subscriber
                                • 62.4K subscribers
                                • Mods:
                                • Ruud@lemmy.world
                                • Loki@lemmy.world
                                • CannaVet@lemmy.world
                                • devve@lemmy.world
                                • curbstickle@anarchist.nexus
                                • ayyy@sh.itjust.works
                                • curbstickle_lw@lemmy.world
                                • BE: 1.0.0-beta.1
                                • Modlog
                                • Instances
                                • Docs
                                • Code
                                • join-lemmy.org