Coordinated Vulnerability Disclosure Readiness of Romanian Public Institutions: A Two-Vantage-Point RFC 9116 Census with Retrospective Web-Archive Analysis
收藏资源简介:
A census of RFC 9116 (security.txt) adoption among Romanian public institutions. Measured on 30 July 2026 from two vantage points: a residential connection in Romania, and a commercial data centre in Germany. Same code, and an external control group in every run. Two sets of domains were measured. The first: all 588 unique domains in the official gov.ro subdomain registry, 2024 edition. The second: 62 public institutions, in nine categories. Cybersecurity bodies, ministries, city halls, hospitals. Result: one institution publishes a security.txt. Its Expires field lapsed on 1 December 2025. Zero conformant and valid files in either set. The dataset includes the full method note and the complete measurement tooling. 532 evidence captures, with response headers and SHA-256 manifests from both vantage points. A retrospective analysis of the Internet Archive index covering four years, and the reconstructed chronology of the only file found. Three things the method adds. A seven-state classification. It separates expired files from absent ones, and both from refused requests. An external control group, measured in every run. A result of zero has to prove the instrument could see. A documented false positive. Internet Archive index metadata alone does not establish that a file existed. All measurements used HTTP GET requests on standardised public paths. No port scanning. No credential testing. No bypassing of access controls.



