in ,

The “security.txt” proposal reached last step in the IETF process, Hacker News


    

Last Call:(A Method for Web Security Policies) to Informational RFC

              

                 

The IESG has received a request from an individual submitter to consider the  following document: - 'A Method for Web Security Policies'    as Informational RFC    The IESG plans to make a decision in the next few weeks, and solicits final  Comments on this action. Please send substantive comments to the[email protected]mailing lists byPayeer-  - . Exceptionally, comments may  be sent to[email protected]instead. In either case, please retain the beginning  of the Subject line to allow automated sorting.    Abstract         When security vulnerabilities are discovered by independent security     Researchers, they often lack the channels to report them properly.     As a result, security vulnerabilities may be left unreported. This     document defines a format ("security.txt") to help organizations     describe the process for security researchers to follow in order to     report security vulnerabilities.          The file can be obtained viahttps://datatracker.ietf.org/doc/draft-foudil-securitytxt/  IESG discussion can be tracked viahttps://datatracker.ietf.org/doc/draft-foudil-securitytxt/ballot/    No IPR declarations have been submitted directly on this I-D.        

           
    
****************** (Read More) ****************

What do you think?

Leave a Reply

Your email address will not be published. Required fields are marked *

GIPHY App Key not set. Please check settings

Layered Programming, Hacker News

New YouTube policy tries to ban “implied” threats, “malicious” insults, Ars Technica

New YouTube policy tries to ban “implied” threats, “malicious” insults, Ars Technica