76% of 623 EU software vendors have no security.txt ahead of the CRA 24h rule

gilsha 15 points 6 comments August 26, 2026
cradrill.com · View on Hacker News

Discussion Highlights (5 comments)

toomuchtodo

For those on Cloudflare, it's a toggle to enable this and provide the necessary values. https://developers.cloudflare.com/security-center/infrastruc...

reconnecting

What is the difference? https://securitytxt.org/

michaelt

Those of you who publish a security.txt - how many reports do you get, and what's the typical quality level? If I push to add one to my employer's website, will our security team thank me for doing so?

sudorm-rf--no-p

Recently I let claude write a script to export some data from a website. While testing the script I came across a bug that leaked the e-mail address of other users, potentially also more data related to the session. Upon discovery Claude did recommend to check for a security.txt, but none was available. Sent a mail to their support instead. A security.txt with further instructions and maybe a PGP key would have been nice…

flowerbreeze

The guidance provided about CRA is difficult to follow and does not in any reasonable way cover proportional guidance for SMEs as it claims to do, but it seems websites/server side products are not be subject to CRA as they are not considered digital products executing on consumer systems? The only websites that should require it are the ones that provide downloadable software or software that is used on digital products. And it seems that European alternatives site lists primarily SaaS and only a few others?

Semantic search powered by Rivestack pgvector
4,560 stories · 41,176 chunks indexed