Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
76% of 623 EU software vendors have no security.txt ahead of the CRA 24h rule (cradrill.com)
16 points by gilsha 35 days ago | hide | past | favorite | 8 comments


The guidance provided about CRA is difficult to follow and does not in any reasonable way cover proportional guidance for SMEs as it claims to do, but it seems websites/server side products are not subject to CRA as they are not considered digital products executing on consumer systems?

The only websites that should require it are the ones that provide downloadable software or software that is used on digital products. And it seems that European alternatives site lists primarily (pure) SaaS and only a few others?


Those of you who publish a security.txt - how many reports do you get, and what's the typical quality level?

If I push to add one to my employer's website, will our security team thank me for doing so?


0 since June or so


We did something similar few days ago. https://cradata.eu/datasets#cra-exposure-study-2026 Almost identical results: Across all 342 manufacturers Publish a valid RFC 9116 security.txt 24 of 342 or 7% Publish any security.txt 34 of 342 or 9.9% Publish a discoverable CVD policy20 of 342 or 5.8% Publish neither, confirmed by observation 257 of 342 or 75.1%


Recently I let claude write a script to export some data from a website. While testing the script I came across a bug that leaked the e-mail address of other users, potentially also more data related to the session. Upon discovery Claude did recommend to check for a security.txt, but none was available. Sent a mail to their support instead. A security.txt with further instructions and maybe a PGP key would have been nice…


What is the difference?

https://securitytxt.org/


This one is selling an AI summary for $39, while yours is a free explanation.


For those on Cloudflare, it's a toggle to enable this and provide the necessary values.

https://developers.cloudflare.com/security-center/infrastruc...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: