You must log in or register to comment.
No, because it invites beg bounties and slop reports.
If you run any sort of public facing website, you’ll likely get some of those eventually.
No, it’s free real estate for scams, slop and the like.
Yes, but I should probably also put one up on my other domains
I was gonna say you had it in the wrong place, but it looks like you also serve it in the /.well-known/ location as well.
Nice domain!
Do people actually contact you with that?
I have a security.txt with an email to report vulnerabilities and a public key to encrypt sensitive information. The only reports I ever got were on the contract us form, unencrypted.
Nope.
Nope, maybe I should ! Thanks for the reminder !
Why so people ignore that too?





