https://en.wikipedia.org/wiki/Security.txt

Reposted from r/selfhosted.

all 15 comments

sorted by: hot top controversial new old
[–] 4 points 9 hours ago

I do, but with a few tweaks that cut most of the junk the other comments mention:

  • Point Contact: at a dedicated alias, not your main inbox, and filter it hard. If the noise gets bad you can drop the alias without touching anything else.
  • Add a Policy: line linking to a short page that says plainly there is no bug bounty and no payment for reports. Most beg-bounty mails are mass-sent with a payment ask, so this gives you something to point them at and lets you bin them without guilt.
  • Don't forget Expires:, it's actually required by RFC 9116 and a lot of hand-written files leave it out. Set a calendar reminder to bump it.
  • Serve it at /.well-known/security.txt; the root path is only a legacy fallback.

Whether it's worth it for a homelab is debatable, but if you host anything other people rely on (a Matrix/Lemmy instance, a shared Nextcloud), having one real contact path beats someone finding a hole and having nowhere to send it.

  • source
  • [–] 33 points 1 day ago (1 child)

    No, because it invites beg bounties and slop reports.

  • source
  • hideshow 1 child comment
  • [–] 21 points 1 day ago

    No, it's free real estate for scams, slop and the like.

  • source
  • [–] 24 points 1 day ago (4 children)

    Yes, but I should probably also put one up on my other domains

  • source
  • hideshow 4 child comments
  • [–] 7 points 1 day ago (2 children)

    Do people actually contact you with that?

  • source
  • hideshow 2 child comments
  • [–] 3 points 1 day ago

    I have a security.txt with an email to report vulnerabilities and a public key to encrypt sensitive information. The only reports I ever got were on the contract us form, unencrypted.

  • source
  • parent
  • [–] 7 points 1 day ago

    Nope, maybe I should ! Thanks for the reminder !

  • source
  • [–] 3 points 1 day ago

    Why so people ignore that too?

  • source
  • [–] 2 points 1 day ago