Who you gonna call?
Tara Poteat, Frank Li · 2021
The security.txt proposed standard allows organizations to define how security researchers should disclose security issues. While it is still proceeding through the final stages of standardization, major online services have already adopted the standard (such as Google, Facebook, LinkedIn, and Github). In this work, we conduct an empirical investigation into how websites are deploying security.txt. We first monitor security.txt adoption over a 15-month period, identifying the level of deployment for top websites. We also characterize the information being provided through security.txt and issues present in the provided data. Ultimately, our analysis sheds light on how the security.txt mechanism manifests in practice and its implications for vulnerability reporting, particularly for large-scale automated notification campaigns.