Skip to content

Comment on We need a “/heartbleed.txt” standard, and we need it ASAP

Comments

I thought about a "hackers.txt" around the time "humans.txt" got popular. It would be stored not in a publicly accessible location, but in a location where finding it would mean a data leak (private web folder, users.sql).

It would have information like a unique security email contact, bounty for responsible disclosure and congratulations on a job well done.

These heartbleed attacks do scare me. They scare me enough that I get the feeling that resistance is futile. Changing your password on a few sites is not going to help when the opposition controls every bit of fiber between you and the website you're logging in on.

I do think that sites should disclose much more prominently when they were hacked. A few days ago there was the headline "Chrome inadvertently blocks wired.com". I think such a headline should be "Wired possible serving malware for a few hours yesterday". No "heartbleed.txt" hidden away, but a large banner across the top of the site: "We were hacked! Read more here! Update your virus scanners and scan your computer."

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.