{"id":527,"date":"2015-07-24T21:07:15","date_gmt":"2015-07-24T20:07:15","guid":{"rendered":"http:\/\/daniel.hepper.net\/blog\/?p=527"},"modified":"2015-07-24T21:07:15","modified_gmt":"2015-07-24T20:07:15","slug":"why-you-need-a-security-address","status":"publish","type":"post","link":"https:\/\/daniel.hepper.net\/blog\/2015\/07\/why-you-need-a-security-address\/","title":{"rendered":"Why you need a security@ address"},"content":{"rendered":"<p>If you run any kind of webservice, you should set up a security@yourdomain.com email address, display it prominently on your website and make sure it gets read by an employee with a technical background.<\/p>\n<p>Not convinced? As a case study, check out <a href=\"https:\/\/news.ycombinator.com\/item?id=9941459\">this post on HackerNews<\/a>. The OP said he had tried to report a security vulnerability at a messaging and voice services provided, but nobody would listen to him.<\/p>\n<p>The suggestions ranged from full-disclosure to emailing the CTO. I pinged the official Twitter account of the company with a link to the thread, but they brushed it off.&nbsp;Ironically, the company even advertises their service as a security solution on their Facebook page.<\/p>\n<p>After about two hours, a member of the ops team finally chimed in on HackerNews and the issue got addressed. A little later, they also got back to me via Twitter. But the damage was done: people started telling stories of unrelated bad customer service experiences and one person said they are going to evaluate a competitor.<\/p>\n<p>With a security contact prominently visible on the website, the whole thing could have been avoided.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>If you run any kind of webservice, you should set up a security@yourdomain.com email address, display it prominently on your website and make sure it gets read by an employee with a technical background. Not convinced? As a case study, &hellip; <a href=\"https:\/\/daniel.hepper.net\/blog\/2015\/07\/why-you-need-a-security-address\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[10,30],"tags":[],"class_list":["post-527","post","type-post","status-publish","format-standard","hentry","category-security","category-software"],"_links":{"self":[{"href":"https:\/\/daniel.hepper.net\/blog\/wp-json\/wp\/v2\/posts\/527","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/daniel.hepper.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/daniel.hepper.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/daniel.hepper.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/daniel.hepper.net\/blog\/wp-json\/wp\/v2\/comments?post=527"}],"version-history":[{"count":2,"href":"https:\/\/daniel.hepper.net\/blog\/wp-json\/wp\/v2\/posts\/527\/revisions"}],"predecessor-version":[{"id":530,"href":"https:\/\/daniel.hepper.net\/blog\/wp-json\/wp\/v2\/posts\/527\/revisions\/530"}],"wp:attachment":[{"href":"https:\/\/daniel.hepper.net\/blog\/wp-json\/wp\/v2\/media?parent=527"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/daniel.hepper.net\/blog\/wp-json\/wp\/v2\/categories?post=527"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/daniel.hepper.net\/blog\/wp-json\/wp\/v2\/tags?post=527"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}