Hacker News new | ask | show | jobs
by waihtis 1217 days ago
Look for a www.domain-of-the-company.com/security.txt file. That's where you might find a responsible disclosure contact if the company has one (high chance they don't)
2 comments

https://www.netflix.com/security.txt exits, but Apple, Google, Microsoft, and Meta don't have one.
TIL! That's great!

The RFC for it came out April 22 and has backing by quite a few organizations.

https://securitytxt.org/

Doesn't seem like a widely used convention.