Is your internet up to date?

Erratum: in the previous post, I originally mentioned that our octet concert will be at the 22nd of November. This is wrong. The correct date is the 29th of November. The concert will will take place in the Amstelkerk and will start at 14:00.

“Internet.nl is an initiative of the Internet community and the Dutch government,” it says in the footer of the website of internet.nl. The community in question is a community of communities, listed on their about page. Among them is NLNet, an organisation that sponsors specific efforts within projects like Nextcloud, KDE and PostmarketOS. I have my thoughts on the Dutch government, but they are not suitable for this blog.

I was pointed to this rather capable web application by a colleague. At work, it sometimes has a role in testing companies in our supply chain. Internet.nl can test your web or email domain and tell you if you’re using all the modern and reliable internet standards, and if not, how to fix it. My domain now has a 86% score, but that’s only because I’m still not on ipv6.

After testing your domain, you get a percentage and for anything not up to standards, you receive a detailed explanation about why this is important and often how to fix it. One thing I didn’t know about was security.txt, a standard text file that should be available at .well-known/security.txt on your server. It is there to provide contact instructions to someone who has found a weakness in your site. It is adopted by organistations such as Google, the BBC, GitHub, Meta and various governments, among which the Dutch.

Creating this file also had me create two extra slash pages, /thanks and /security-policy, both meant for the internet vigilante who selflessly scours my domain, hunting for weaknesses. The files are there to tell them how to proceed and what to expect of me. Copy them if you want to. You can’t copy my security.txt because it is signed and changing the domain name will make it invalid.

Other things internet.nl focus on are up-to-date keys and software and proper web server security settings. Those are easily fixed by a quick DuckDuckGo search and an extra line in your web server/reverse proxy settings.

As mentioned before, my site receives its daily share of people trying to log in or have it run scripts, mostly assuming there is something here to log into in the first place. I’m not really concerned about those. They mostly receive 404s and 403s, just like the AI bots.

I will have to re-sign my security.txt again when its key expires. This is an extra chore and something to keep track of. I still haven’t been contacted by someone stumbling on a data leak, which means that until now, all I got for my efforts is a higher percentage on internet.nl. I suppose that’s better than the alternative.

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论