Post #4141076
2026-07-27 15:58 UTC
Apropos of nothing, I think it's past time for risks.txt to go alongside robots.txt and security.txt on websites. risks.txt would declare the contents of the organization's risk acceptance log so the $baddies know not to use those issues in attacks.
Replies (7)
-
@ChickenPwny@infosec.exchange 2026-07-27 16:04
@jerry@infosec.exchange lol
-
@rallias@hax.social 2026-07-27 16:09
@jerry@infosec.exchange I believe that's required by 17 CFR 209.106 /s
-
@bradr@infosec.exchange 2026-07-27 16:21
@jerry@infosec.exchange
-
@Epic_Null@infosec.exchange 2026-07-27 16:53
@jerry@infosec.exchange So I am seeing the "Bad Idea" part of this but also... am not totally against this? Only thing I suggest is making it Agentic Aware by making it a risks.md instead. No, I am not entirely sure if I am joking here.
-
@kskoglund@infosec.exchange 2026-07-27 20:18
@jerry@infosec.exchange whatevs.txt
-
@loke@functional.cafe 2026-07-27 15:59
@jerry@infosec.exchange Is that the one that lists all the administrative passwords in order to make sure no one else uses them?
-
@mansr@society.oftrolls.com 2026-07-27 16:01
@jerry@infosec.exchange See also RFC 3514.