Subreddit guide

r/netsec: rules, karma requirements and posting culture

A curated link feed of original security research for working practitioners. Aggressively moderated, quiet in the comments, and closed to tool launches and questions.

Technical Information Security Content & Discussion · Open on Reddit

Members
574k
Created
2007
New posts a day
8.8
Comments on a typical post
2
New posts removed
56%

The short answer

r/netsec publishes no karma or account age number, but most submissions do not make it: only about 43% of posts in our sample stayed up, a third were held by AutoModerator and another 15% were removed by moderators. It is a link subreddit. You submit the original source of a technical write-up with a title that gives context, and the mods judge it on technical merit. Questions, tool announcements, videos, news rewrites and vendor marketing are rejected, and tools and questions go in the monthly discussion thread.

Who posts here

Knowledge levelAdvanced

The rulebook says moderation exists to keep content relevant to an advanced technical audience, and the posts match: exploit chains, sandbox escapes, kernel and firmware bugs, written for people who already know the terms. Nothing is explained for newcomers. Question posts are prohibited outright, and beginners are pointed to a getting started wiki page, the monthly discussion thread and a students subreddit.

  • Vulnerability researchers and red teamers publishing their own findings.
  • Research teams at security vendors, whose write-ups are accepted when they are technical and not sales material.
  • Defenders and engineers who read for detection ideas and patch urgency, and mostly lurk.
  • Academics sharing papers and measurement studies.
  • Open source tool authors, most of whose posts are rejected and sent to the monthly thread.

Karma and account requirements

What it takes to get a post through in r/netsec.

KarmaNot stated publicly. About a third of posts in our sample were held by AutoModerator, so a filter exists, but what it checks is not published.
Account ageNot stated publicly for ordinary posts. For anything commercial, the rules ask for six months or more of quality contributions first.Mods' wording: “submitting quality content or comments to /r/netsec for 6+ months”
Post typeLinks only, in effect. About 98% of posts are links. Question posts, image only posts and video only posts are prohibited.Mods' wording: “No image-only/video-only posts.”
SourceLink to the original research, not a news article about it. Paywalled or registration walled content is not allowed.Mods' wording: “we require that all submitted links be the original source of the information”
TitleMust say what the thing is. A bare product or project name is treated as noise.Mods' wording: “Submission titles should give a brief bit of context for readers”
Quality barSubjective, and stated as such. Posts must be technical and focus on the how.Mods' wording: “all posts are subjectively judged by their technical merit”

What you can post

Post typeSubreddit settingShare of recent posts
TextNot allowed2%
LinkAllowed98%
ImageNot allowed0%
VideoAllowed0%
PollNot allowed0%

Post flairs in use

  • Contains AI 11%
  • PDF <1%
  • Rejected (Low Quality) <1%
  • Rejected (Not Technical Enough) <1%
  • Rejected (Tool Post) <1%

What happens to a new post

Where the most recent posts ended up. Sample size: 400.

  • Stayed up43%
  • Removed by Reddit's filters8%
  • Held by AutoModerator33%
  • Removed by moderators15%
  • Deleted by the author1%

Reddit counts a removal by the subreddit's own AutoModerator rules as a moderator removal, so that share is not all human. Held by AutoModerator means the post is waiting in the mod queue.

The rules, in the mods' words

  1. 1

    Always link to the original source.

    We require that all submitted links be the original source of the information; whether it's a blog post, conference presentation, paper, video, mailing list item, etc. The only exceptions made are for content that is hosted on sites like YouTube or SlideShare, or if the original source is no longer available online.

  2. 2

    Titles should provide context.

    Submission titles should give a brief bit of context for readers; being terse yet informative is ideal.

  3. 3

    Check the new queue for duplicates.

    To avoid being flooded with news-of-the-week style stories, we remove links to subject matter that has already had recent coverage in the subreddit; should a new article be submitted which adds significant depth to the analysis, reach out to us - we're often willing to make exceptions for high quality content.

  4. 4

    Commercial advertisement is discouraged.

    Our subscribers are here for interesting technical content, not to line your wallet. We don't allow the posting of commercial content unless the submitting user has both a preexisting relationship with our community, and a personal stake in its success. If you have not been submitting quality content or comments to /r/netsec for 6+ months and have had a minimal number of removed submissions, you should refrain from posting links to commercial services or products.

  5. 5

    Don't create unnecessary conflict

    Discussions should remain polite and civil; any hostility toward other users is likely to draw the ire of the moderators and a sharp rap from the banhammer.

  6. 6

    No prohibited content or sources

    /r/netsec requires that all posts be technical in nature and high quality. Multiple topics and sources are not permitted to be submitted due to conflicts with this requirement; our fulltext list of prohibited topics and sources, linked below, provides more details.

  7. 7

    No low-quality or political posts

    Submissions that are low quality or political in nature (instead of technical) are not permitted on /r/netsec and are subject to moderation.

These are the rules as archived in January 2025. Rules change. Check the sidebar before you post.

The culture

r/netsec describes itself as a community curated aggregator of technical security content, and it behaves like an edited reading list. It has about 574,000 members but only around 9 posts a day, because most submissions never appear. In our sample 43% stayed up, about a third were held by AutoModerator, 15% were removed by moderators and about 8% were caught by Reddit's filters.

What gets through is original research: a named vulnerability with the root cause and the exploit path, a reverse engineering write-up, a measurement study with methods and data. Titles are plain and specific, often with a CVE number, and almost none are questions. Comment sections are small, with a median of 2 comments, and the comments that appear are a few sentences of technical reaction. A post with 50 points is doing well here.

AI is the current pressure point. About 11% of posts carry a Contains AI flair, and a lot of rejected submissions are AI agent security tools or write-ups about them. Readers are openly tired of machine written text, and praise a piece for not reading like slop. Research about how AI systems fail does get accepted. Products built around that topic mostly do not.

What lands

  • A full write-up of a pre-authentication remote code execution bug in widely deployed enterprise software, with the chain explained step by step.
  • A finding with a concrete, checkable number in the title, such as how many apps a set of leaked keys could impersonate.
  • Deep internals work: bootloaders, kernel subsystems, sandbox escapes, platform changes that break existing assumptions.
  • Original measurement studies that publish their method, rubric and data.
  • A dry or funny title on top of serious research. The humour is welcome when the content holds up.

What gets removed or ignored

  • Tool and project announcements. Rejected (Tool Post) was by far the most common moderator removal flair in our sample, and open source does not exempt you.
  • Videos and secondhand sources, flagged as Rejected (Bad Source).
  • Question and discussion prompts as posts. They are flagged as Rejected (Question) and belong in the monthly thread.
  • A second write-up of a topic that was covered recently, unless it adds real depth.
  • News articles, curated lists, social media posts, tech support requests, political posts and anything behind a paywall or sign-up form.

The unwritten rules

  • The label Tool Post is applied broadly. Research write-ups that centre on the author's own repo or product were rejected under it too, so lead with the finding, not the thing you built.
  • If you are the author or work for the publisher, say so in a comment and give the method and caveats. That is normal here and goes down well.
  • Do not expect conversation. Most posts get a couple of comments, and upvotes are modest.
  • Comments that tack a product link onto a generic reaction stand out badly. Only about 6% of comments contain a link at all.
  • The mods say they use short bans freely instead of warnings. Reposting a rejected link is a bad idea.

Self-promotion

The rule is that commercial content is only allowed from people with a preexisting relationship with the community and a personal stake in it, and it sets the bar at six months or more of quality submissions or comments with few removals. The sidebar is blunter and lists commercial advertisements under prohibited topics. In practice vendor research blogs appear in the feed all the time, because a detailed write-up of a real bug is judged as research. What gets removed is anything shaped like a launch: a tool, a product feature, a repo. Tool links are allowed in the monthly discussion and tool thread, and that is where they should go.

How people write here

Typical post length
69 words
Typical title length
10 words
Titles phrased as a question
3%
Typical comment length
25 words
Comments that include a link
6%
Posts that carry a flair
14%

When people post

  1. 0:00 UTC, 7
  2. 1:00 UTC, 7
  3. 2:00 UTC, 7
  4. 3:00 UTC, 13
  5. 4:00 UTC, 9
  6. 5:00 UTC, 12
  7. 6:00 UTC, 14
  8. 7:00 UTC, 18
  9. 8:00 UTC, 10
  10. 9:00 UTC, 23
  11. 10:00 UTC, 17
  12. 11:00 UTC, 15
  13. 12:00 UTC, 20
  14. 13:00 UTC, 34
  15. 14:00 UTC, 27
  16. 15:00 UTC, 24
  17. 16:00 UTC, 25
  18. 17:00 UTC, 21
  19. 18:00 UTC, 22
  20. 19:00 UTC, 20
  21. 20:00 UTC, 18
  22. 21:00 UTC, 20
  23. 22:00 UTC, 12
  24. 23:00 UTC, 5

New posts by hour of day, UTC.

The regulars

The accounts that showed up most in our sample. Worth reading before you post: they set the tone, and they are usually the first to reply.

Most active posters

  1. u/fagnerbrack7 posts
  2. u/natcoba6 posts
  3. u/acorn2223 posts
  4. u/dx7r__3 posts
  5. u/No-Peanut-69883 posts

Most active commenters

  1. u/No-View333318 comments
  2. u/lowlydrunkenness6357 comments
  3. u/bitbutter6 comments
  4. u/AlexandreDaubois6 comments
  5. u/Big_Combination98905 comments

Top keywords

The words and phrases that show up far more often here than in other communities, from recent posts in r/netsec.

  • rce 21 posts
  • security 33 posts
  • code 32 posts
  • sandbox 11 posts
  • vulnerabilities 10 posts
  • vulnerability 12 posts
  • privilege escalation 8 posts
  • bypass 10 posts
  • unauthenticated 9 posts
  • injection 10 posts
  • code execution 8 posts
  • leak 9 posts
  • execution 13 posts
  • exploit 9 posts
  • linux 10 posts
  • trust boundaries 4 posts
  • ssh key 4 posts
  • local privilege 4 posts
  • authentication 9 posts
  • unowned code 3 posts
  • mmr evidence 3 posts
  • latent core 3 posts
  • installed unowned 3 posts
  • inside corporate 3 posts
  • hermes installed 3 posts
  • core trust 3 posts
  • code inside 3 posts
  • aegis latent 3 posts
  • chained 5 posts
  • hacking 6 posts
  • bug 10 posts
  • ai coding 7 posts
  • encryption 6 posts
  • pre-auth 5 posts
  • llm 13 posts
  • pre-auth rce 4 posts
  • chain 10 posts
  • tls 5 posts
  • credential leak 3 posts
  • corporate networks 3 posts

Recurring topics: ai, rce, agent, exploit, security, cve, open-source, phishing, attack, network.

Posts that did well

Growth

  1. 201263k
  2. 201389k
  3. 2014120k
  4. 2015144k
  5. 2016177k
  6. 2017232k
  7. 2018281k
  8. 2019346k
  9. 2020395k
  10. 2021435k
  11. 2023489k
  12. 2024513k
  13. 2025544k
  14. 2026574k
  • r/blueteamsec
  • r/Malware
  • r/cybersecurity_help
  • r/SecOpsDaily
  • r/Cybersecurity101
  • r/MalwareAnalysis
  • r/InfoSecNews
  • r/security
  • r/dfir
  • r/AskNetsec

Common questions

How much karma do you need to post in r/netsec?

No number is published. About a third of posts in our sample were held by AutoModerator and a further 15% were removed by moderators, so expect your submission to be reviewed before it shows. The published tests are about content: original source, technical depth, a title with context.

Can I promote my security tool or product in r/netsec?

Not as a post. Tool announcements are the most commonly rejected submissions, and the rules discourage commercial links from anyone without six months or more of quality participation. Share tools in the monthly discussion and tool thread. Technical research published on a company blog is accepted if it stands on its own.

Can I ask a question in r/netsec?

Not as its own post. The sidebar lists question posts as prohibited, and moderators flag them as rejected. Ask in the monthly discussion thread, which is open to questions related to network security.

What kind of posts work in r/netsec?

Links to original technical write-ups. About 98% of posts are links. Vulnerability research with a clear root cause and exploit path does best, along with reverse engineering and measurement studies. Titles run about 10 words and say exactly what was found.

Data as of October 4, 2026. Numbers come from public Reddit data (the Arctic Shift archive and GummySearch) sampled on this date. Removal share counts posts taken down by moderators, AutoModerator or Reddit's own filters. Banner and icon belong to the community. Moderators change rules without notice, so treat the sidebar as the final word.

Retro engraving of two spacecraft dockingFree audit

See what Reddit says about you.

Not a generic audit. Your actual numbers: where you get mentioned, where your three closest competitors get mentioned instead, and what your own analytics say about traffic you are already losing.

Drops your email into the two-minute application.