The billion-dollar security.txt problem
sansec.io·5d·
Discuss: Hacker News
🔓DRM Analysis
Preview
Report Post

Yesterday, Sansec discovered an active keylogger at an external site of one of America’s largest banks. The malware was harvesting private information from over 200,000 potential victims. We detected it within hours of the attack going live. No other security vendor had flagged it.

Then came the hard part: telling someone.

The bank has no security.txt file. No public bug bounty program. No obvious security contact. We sent emails to generic addresses. We reached out via LinkedIn. Hours passed while the malware kept running.

Why big companies are hard to reach

This isn’t an isolated case. The larger the company, the harder it is to report security incidents to the right people.

Procedures don’t accommodate outliers. Large organizations run on standardized processe…

Similar Posts

Loading similar posts...

Keyboard Shortcuts

Navigation
Next / previous item
j/k
Open post
oorEnter
Preview post
v
Post Actions
Love post
a
Like post
l
Dislike post
d
Undo reaction
u
Recommendations
Add interest / feed
Enter
Not interested
x
Go to
Home
gh
Interests
gi
Feeds
gf
Likes
gl
History
gy
Changelog
gc
Settings
gs
Browse
gb
Search
/
General
Show this help
?
Submit feedback
!
Close modal / unfocus
Esc

Press ? anytime to show this help