557 points by k1m 6 days ago | 220 comments | View on ycombinator
Latty 6 days ago |
fmajid 6 days ago |
- use standard input field names password managers recognize - disable autocompletion and autocapitalization on the login field
- if it's an email, use the correct HTML5 input type
- don't have a form with just a login email and force the user to click to enter the password
- follow NIST SP 800-53, e.g. no SMS 2FA and no arbitrary password rotation and composition rules
Or how many sites that have a form with only one input don't automatically focus on it.
kaiokendev 6 days ago |
It is ironic though that the site itself fails to employ even its own "required" practices, but that's more of an aside.
zophi 6 days ago |
_ache_ 6 days ago |
I don't get the goal of the website. It's averted as a specification, but to spec what ?! Everything is sourced to another "source of truth".
selfhoster1312 6 days ago |
Oh yes, it's produced by a Wordpress "SEO" expert and private investor using Claude LLM. What a surprise. A man who built a fortune destroying the internet we loved with advertisement slop now working on destroying whatever's left with LLM slop.
mschuster91 6 days ago |
ItsABytecode 6 days ago |
unchar1 6 days ago |
Seems a bit ironic considering that it's supposed to be a specification on how a website should be.
bmn__ 5 days ago |
WA 6 days ago |
baliex 6 days ago |
I’ll be using this to add some extra tags to my pages.
It looks like there are some features noted as “required” that are actually required by the spec (e.g. a title tag), and others that are required by opinion (e.g. https) so there’s an element^ of pragmatic best practice being recommended.
I find it curious that setting a colour hint for the browser is recommended. I’m one for letting the browser look as vanilla as possible and letting my pages do the talking.
^Pun not intended, blink and you’ll miss it
rsolva 5 days ago |
I planed to make something like this as a skill for my self, but pasting this into any agent chat works like a charm. I just had my local model (Qwen3.6 27B / pi) make a list of all the required standards an older hugo site of mine was missing, make a todo list and then run through the whole thing one by one, giving me chance to review each change.
It even made the missing favicon by cropping out the symbol from the logo, and it looks good!
PullPage 4 days ago |
ramon156 6 days ago |
Can't wait for an ISO alternative that is agent-driven, or slot machines that are run by LLMs
npc73x 6 days ago |
Kwpolska 6 days ago |
Yeah, mostly slop. I wonder why the slop slingers never disable Claude's self-attribution, and are too lazy to commit themselves, are they proud that they're delegating everything to a slop machine?
tanepiper 6 days ago |
undefined 6 days ago |
replwoacause 5 days ago |
sammy2255 6 days ago |
cbm-vic-20 6 days ago |
incognitoninja 6 days ago |
Dwedit 6 days ago |
Nizoss 6 days ago |
sinansaka 6 days ago |
cush 6 days ago |
bag_boy 6 days ago |
franze 6 days ago |
.. as the webmaster implemented something that they might thought has an impact (false sense of impact), but has zero
so net gain negative
i consider such lists harmful - a good website is one that supports the goal of the website providers and its desired users (some of these users might be bots)
a bad website is a website that does everything for everyone just because
andai 6 days ago |
tosti 6 days ago |
MagicMoonlight 5 days ago |
This entire site is just AI slop, defeating the point of the site. If an AI already knows it, then it doesn’t need to read the site.
pratikdeoghare 6 days ago |
BUT
Some people memorize these things. Take them too seriously. You are thought stupid if you don't know them. Somewhere someone then makes a story on Jira to verify that your product does all of these things and you have to convince them that we are fine without them or we don't need all of them etc.
todotask2 6 days ago |
Many web and SEO agencies have let technical debt build up over the years. I raised some issues to them, but didn’t hear back.
After auditing a million websites, can we fix them? We could rebuild the web.
mockbuild 5 days ago |
austin-cheney 5 days ago |
baisampayans 6 days ago |
outageroom 6 days ago |
Talpur1 5 days ago |
undefined 6 days ago |
vladsiu 6 days ago |
cawksuwcka 5 days ago |
ai_fry_ur_brain 6 days ago |
openports 5 days ago |
nimitlabs 6 days ago |
tzs 6 days ago |
throwaw12 6 days ago |
knowmygpa 6 days ago |
But right now, when AI can just spit out everything you have on website faster and in a more personalized way then i dont think that people would wanna use this much.
Just my perspective, dont wanna be rude
BubbleRings 6 days ago |
Look at the part of the website at my first link, that describes how to do an audit using their guidelines, then after that, run such an audit on my website at the second link.
https://specification.website/
Www.my-personal-squarespace-site-not-a-real-url.com
(To be entirely clear, not because agents won't be a relevant thing, although certainly I have my doubts, but because I believe even if they are a relevant thing, requiring special allowances from sites undermines the whole point, and such things will only end up used by bad actors to mismatch what agents see to what humans see, and so will be intentionally ignored.)