Erik van Straten<p><span class="h-card" translate="no"><a href="https://phpc.social/@valorin" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>valorin</span></a></span> : thanks, I wasn't aware of the existence of an RFC for a default change-password file!</p><p>For those interested: <a href="https://internet.nl" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">internet.nl</span><span class="invisible"></span></a> checks any webserver for, among a lot of other things, the existence of the security.txt file (it shows its results in English, you don't have to know what Goudse kaas, stroopwafels and hagelslag mean ;-)</p><p>Best practices: <a href="https://internet.nl" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">internet.nl</span><span class="invisible"></span></a> checks for lawful requirements of Dutch (Netherlands) governmental websites. After more than a year since that law came into effect, still a lot of govt. websites do not fully comply. In particular, many have still not set up HSTS correctly, such as Almere (<a href="https://internet.nl/site/almere.nl/2957791/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">internet.nl/site/almere.nl/295</span><span class="invisible">7791/</span></a> - not detected by <a href="https://developer.mozilla.org/en-US/observatory/analyze?host=almere.nl" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">developer.mozilla.org/en-US/ob</span><span class="invisible">servatory/analyze?host=almere.nl</span></a>).</p><p>Unfortunately HSTS (which too often does not work) still has to help internet users, as browsers still do not *enforce* https connections in a sensible way (<a href="https://infosec.exchange/@ErikvanStraten/113045241408077702" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">infosec.exchange/@ErikvanStrat</span><span class="invisible">en/113045241408077702</span></a>).</p><p>(Coen Wesselman <span class="h-card" translate="no"><a href="https://mastodon.nl/@wsslmn" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>wsslmn</span></a></span> : do you like the idea of adding a check for "/.well-known/change-password", and if so, is that something you could ask to be included in the tests by internet.nl?)</p><p><a href="https://infosec.exchange/tags/changepassword" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>changepassword</span></a> <a href="https://infosec.exchange/tags/change_password" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>change_password</span></a> <a href="https://infosec.exchange/tags/security_txt" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security_txt</span></a> <a href="https://infosec.exchange/tags/websites" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>websites</span></a> <a href="https://infosec.exchange/tags/website" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>website</span></a> <a href="https://infosec.exchange/tags/webserver" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>webserver</span></a> <a href="https://infosec.exchange/tags/SIDN" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SIDN</span></a> <a href="https://infosec.exchange/tags/internet_nl" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>internet_nl</span></a> <a href="https://infosec.exchange/tags/HSTS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>HSTS</span></a> <a href="https://infosec.exchange/tags/MDN" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>MDN</span></a></p>