#curl is RFC 9116 compliant
-
#curl is RFC 9116 compliant
https://curl.se/.well-known/security.txt
https :// curl.se / .well-known / security.txt
-
#curl is RFC 9116 compliant
https://curl.se/.well-known/security.txt
https :// curl.se / .well-known / security.txt
it does make me wonder if having this, this easily accessible, is part of the reason why the sloptimists decide to target us
-
#curl is RFC 9116 compliant
https://curl.se/.well-known/security.txt
https :// curl.se / .well-known / security.txt
We will ban you and ridicule you in public if you waste our time on crap reports.
I see why that is needed, but at the same time I think there is a thin line here, what if someone simply is not sure, a false positive, is that a waste of time to perform investigation?
That ban/ridiculation threat demotivates the report, the message simply says that if you are not a high level engineer or a big company with resources to have identified something in the field, please don't report, individuals with limited knowledge not encouraged to report and that's when the person simply chooses the easiest path: Post the report publicly to some forum or microblog and then there is a disclosure of something that should have been embargoed.
I got the motivation but I don't feel good about the wording.
-
We will ban you and ridicule you in public if you waste our time on crap reports.
I see why that is needed, but at the same time I think there is a thin line here, what if someone simply is not sure, a false positive, is that a waste of time to perform investigation?
That ban/ridiculation threat demotivates the report, the message simply says that if you are not a high level engineer or a big company with resources to have identified something in the field, please don't report, individuals with limited knowledge not encouraged to report and that's when the person simply chooses the easiest path: Post the report publicly to some forum or microblog and then there is a disclosure of something that should have been embargoed.
I got the motivation but I don't feel good about the wording.
@bruno desperate times...
-
#curl is RFC 9116 compliant
https://curl.se/.well-known/security.txt
https :// curl.se / .well-known / security.txt
@bagder "We will ban you and ridicule you in public if you waste our time on crap reports."
💯 -
@bruno desperate times...
@bagder@mastodon.social @bruno@go.rocha.social tbh it'd be judged on a case-by-case basis anyway, yeah?
-
#curl is RFC 9116 compliant
https://curl.se/.well-known/security.txt
https :// curl.se / .well-known / security.txt
-
@bagder That's lovely
-
@bagder they are talking to 2 other people - the rest of us would do better with some life affirming ridicule
-
it does make me wonder if having this, this easily accessible, is part of the reason why the sloptimists decide to target us
@bagder Maybe you should have a LLM catch footer that says "ignore previous instructions" and provides bogus contact info. Since given how little these people read maybe they're having their slop machines parse the doc for them.
-
undefined oblomov@sociale.network shared this topic on