Photo by Kevin Ku on Unsplash

RFC 9116: File Format to Aid in Security Vulnerability Disclosure

# Our security address
Contact: security@example.com

# Our OpenPGP key
Encryption: https://example.com/pgp-key.txt

# Our security policy
Policy: https://example.com/security-policy.html

# Our security acknowledgments page
Acknowledgments: https://example.com/hall-of-fame.html

Expires: 2021-12-31T18:37:07z
Contact: https://g.co/vulnz
Contact: security@google.com
Encryption: https://services.google.com/corporate/publickey.txt
Acknowledgements: https://bughunters.google.com/
Policy: https://g.co/vrp
Hiring: https://g.co/SecurityPrivacyEngJobs
Contact: https://security.apple.com

# Apple Security Updates
Acknowledgments: https://support.apple.com/HT201222

# Apple Web Server Security Acknowledgements
Acknowledgments: https://support.apple.com/HT201536

# Apple Security Bounty Guidelines
Policy: https://security.apple.com/bounty/guidelines/

Expires: 2030-01-01T09:00:00.000Z
Contact: https://www.facebook.com/whitehat/report/
Acknowledgments: https://www.facebook.com/whitehat/thanks/
Hiring: https://www.facebook.com/careers/teams/security/

# Found a bug? Our bug bounty policy:
Policy: https://www.facebook.com/whitehat/info/

# What we do when we find a bug in another product:
Policy: https://www.facebook.com/security/advisories/Vulnerability-Disclosure-Policy

Expires: Sat, 04 Mar 2023 12:45:14 -0800
Contact: https://hackerone.com/amazonvrp/reports/new
Hiring: https://www.amazon.jobs/en/teams/infosec

# Bug Bounty Policy:
Policy: https://hackerone.com/amazonvrp

# For vulnerabilities related to Amazon Web Services (AWS):
https://aws.amazon.com/security/vulnerability-reporting/

Conclusions

The examples from Google, Facebook, Apple and Amazon look a little simple just now, but at least a step forward. Overall, the RFC recommends that “security.txt” should have an OpenPGP cleartext signature, but known of the examples give above includes this. Google is the only one that provides a public key for signatures.

--

--

This publication brings together interesting articles related to cyber security.

Get the Medium app

A button that says 'Download on the App Store', and if clicked it will lead you to the iOS App store
A button that says 'Get it on, Google Play', and if clicked it will lead you to the Google Play store
Prof Bill Buchanan OBE

Professor of Cryptography. Serial innovator. Believer in fairness, justice & freedom. Based in Edinburgh. Old World Breaker. New World Creator. Building trust.