Re: [Last-Call] Last Call: <draft-foudil-securitytxt-08.txt> (A Method for Web Security Policies) to Informational RFC

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hi Paul

We can’t be totally certain all the time but researchers have certainly mentioned how they found the contact details (and VDP) when they contact us in the past. The VDP (https://www.bbc.com/backstage/security-disclosure-policy/) and security.txt are a pairing, each references the other and we included contact details in the VDP so that researchers don’t have to go to security.txt if they didn’t find our VDP that way – we don’t really care how they find it, we just want their reports. As for DNS, that’s not something I know about, we’re a big org so someone might have been proactive but again, we just advertise the address where we can for ease of use. https://medium.com/@dr.spitfire/a-fight-for-duplicate-marked-bug-story-of-bbc-hall-of-fame-16f9c8215315 is not our content.

Having a standardised method of discovery is definitely helpful from both a time/effort-saving and reassuring the researcher that we’re trying to behave responsibly perspective. As I mentioned previously, both manual and automated discovery via a standard means/location is something we think is very valuable.

Hope that helps.

Cheers

Neil Craig
Lead Technical Architect
BBC Online Technology Group
London W12 | BC4 A3

From: Paul Wouters <paul@xxxxxxxxx>
Date: Thursday, 12 December 2019 at 12:54
To: Neil Craig <Neil.Craig@xxxxxxxxx>
Cc: "last-call@xxxxxxxx" <last-call@xxxxxxxx>
Subject: Re: [Last-Call] Last Call: <draft-foudil-securitytxt-08.txt> (A Method for Web Security Policies) to Informational RFC

How do you know it can from there ? I see lots of hits for the published contact security@xxxxxxxxx, eg



You even publish that same email address in a DNS TXT record with a mailto: link.

It seems more that you added the address at yet another location with the same contact information? So I am a bit confused how you reached your conclusion that people found that email address via this drafts mechanism.

Paul

Sent from my iPhone

On Dec 12, 2019, at 04:23, Neil Craig <Neil.Craig@xxxxxxxxx> wrote:

Hello

Via Twitter, I’ve become aware that there’s an upcoming vote on "draft-foudil-securitytxt-08.txt (A Method for Web Security Policies) to Informational RFC”, https://tools.ietf.org/html/draft-foudil-securitytxt-08.

I’d like to add a note in favour of ratification from a BBC perspective. We adopted the security.txt standard (https://www.bbc.co.uk/.well-known/security.txthttps://www.bbc.com/.well-known/security.txt) in August 2018 and have seen some very significant benefit from it, as evidenced in our public acknowledgements page: https://www.bbc..com/backstage/security-disclosure-policy/acknowledgements. All but the very first vulnerability on that page was reported via security.txt and for every acknowledged vulnerability, there are around 5 more which are duplicates or which, on inspection, don’t meet our scope requirements.

Some side benefits of deploying security.txt have been a raising of the profile of online security within the BBC and really fantastic engagement from the web security community, this has led to cooperation with several other organisations and individuals.

We would very much like to see security.txt ratified as a standard in order to promote the usual benefits, including consistency of usage, improved interoperability and adoption by mainstream applications and services.

As a potential third-party endorsement, I noticed recently that Shodan...io has now integrated security.txt detection and listing, see https://www.shodan.io/host/212.58.249.210 as an example.

I hope that’s useful. I’m very happy to provide any further information you might need, please just let me know if that’s the case.

Many thanks

Neil Craig
Lead Technical Architect
BBC Online Technology Group
London W12 | BC4 A3
-- 
last-call mailing list
last-call@xxxxxxxx
https://www.ietf.org/mailman/listinfo/last-call

[Index of Archives]     [IETF Annoucements]     [IETF]     [IP Storage]     [Yosemite News]     [Linux SCTP]     [Linux Newbies]     [Mhonarc]     [Fedora Users]

  Powered by Linux