New: warm up Reddit accounts. You own them.
Rankhog
Subreddit guides

r/AskNetsec rules, stats, and what to post

A source-backed Rankhog guide to r/AskNetsec: public rules, community context, posting fit, and startup-promotion risk before you publish.

By Anthony Riera, founder and operator of Rankhog.

Subreddit guides combine public Reddit source URLs, captured rules, visible verification dates, and Rankhog's account-safety workflow.

Current public stats

Members
263,692
Verified
September 8, 2026
Category
Technical product and developer communities

Rules can change, so Rankhog keeps verification dates and the original public Reddit sources visible.

Rule summary

  • All submissions must be in the form of a question: All posts must be in the form of a question relevant to infosec. Soliciting "guidance", "feedback", or "thoughts" without any specific answerable question is not sufficient. Asking vague "has anyone ever" questions is also not sufficient. Questions must be specific, relevant, and answerable.
  • All submissions must be relevant to information security: To keep with the spirit of this sub, questions should be related to information security in an enterprise, large organization, or SOHO context. Homework, industry surveys, and beginner questions are most likely not relevant and should be asked in their respective subreddits. This rule is subject to moderator discretion.
  • Questions about possible or confirmed incidents must contain sanitized technical evidence: r/AskNetsec is not intended to assist with mysterious computing events, stalkers, or incidents without factual evidence of a technical nature.
  • No low effort questions: If you expect someone to take the time to answer a question and provide the help, you are expected to provide as much information as possible. Please include all previous troubleshooting, operating systems, application patch level, etc. If you think it might be relevant to the questions, then include it.
  • Be civil and professional: Always abide by Reddit.com site rules, and use Reddiquette and professional judgment as a guideline. This rule is subject to moderator discretion.
  • Do not ask for assistance in committing a crime, encourage crime, or offer criminal services: We are open to aiding people as a community in Penetrating Testing (Pen-Testing), Capture the Flag (CTFs), and red-team related scenarios, but Moderators have the right to remove/lock any comment or post that could be deemed to have criminal intent. If you believe this wrong, please let us know why and provide more information about the current situation. Your post was moderated on most likely because of not having enough info. Breaking this rule intentionally will result in immediate ban.
  • Don't spam or excessively showcase your own content. No referral or affiliate links: Repeatedly posting the same content or content from the same source, is considered spam. Posting low-quality content, blogs, vlogs, or YouTube videos is considered spam. Self-promotion and/or shilling (not disclosing a relationship with a source being promoted) are considered spam. If someone asks a question about a specific product, service, or organization, and you are a direct representative of that organization, you may address the question so long as you clearly identify yourself as such.
  • No questions about password managers: Question about password managers do not typically fall within the scope of this sub. Please refer to r/PasswordManagers for further assistance.
  • No questions about Career Advice, homework, or beginner questions.: /AskNetsec is more focused on technical questions. That means that questions related to career advice, what cert to get, school work, how to get started, etc, should be posted to places like: r/SecurityCareerAdvice, /r/NetSecStudents, /r/ITCareerQuestions, etc.
  • No low effort posts: If you expect someone to take the time to answer a question and provide the help, you are expected to provide as much information as possible. Please include all previous troubleshooting, operating systems, application patch level, etc. If you think it might be relevant to the questions, then include it. If you need help identifying what information you need [message the mods](https://www.reddit.com/message/compose?to=/r/AskNetsec) and we can help.
  • No posts asking about being hacked: This sub is reserved for network/server/information security questions. Asking questions about home computer or phone being hacked involve too many details. This includes clicking suspicious links/emails, your phone/computer acting weird, or if you believe you are being cyber stalked. To keep yourself safe, change your passwords (do not reuse passwords), enable 2FA, install a virus scanner, and use a password manager (/r/passwordmanagers).

Works well

  • Ask a specific technical question about configuring a firewall rule in an enterprise environment, including your OS, patch level, and what you have already tried.
  • If someone asks about a product you represent, reply with a clear disclosure that you work for the company, then answer their technical question directly.
  • Post a question about a SOHO network segmentation issue with sanitized technical evidence and full context about your setup and troubleshooting steps.

Avoid

  • Posting anything that is not a specific, answerable question about information security.
  • Asking for vague guidance, feedback, or thoughts without a concrete question.
  • Posting career advice questions, homework, or beginner questions.
  • Posting questions about password managers.
  • Posting about personal devices being hacked, suspicious links, or cyber stalking.
  • Posting low effort questions without technical details like operating systems and patch levels.

What actually works in r/asknetsec

These are the highest scoring posts Rankhog observed in r/asknetsec over the past month, with what each one did differently. Rankhog watches this community continuously, so it sees posts when they are published and again as they climb.

  1. Screenshot of a post in r/asknetsec titled "A fraudster in Spain passed video ID checks 38 times with a live AI face swap. What exposed him was a one-second…" with 47 upvotes
    Upvotes
    47
    Comments
    27
    Posted
    Aug 18, 2026

    Why it worked

    • Asks the community a question instead of announcing something
    • Short paragraphs rather than one block of text

    Read the full thread on Reddit

  2. Screenshot of a post in r/asknetsec titled "How do you find AI-built apps (Replit, Lovable, Vercel) that nobody told security about?" with 44 upvotes
    Upvotes
    44
    Comments
    26
    Posted
    Aug 31, 2026

    Why it worked

    • Asks the community a question instead of announcing something
    • Short paragraphs rather than one block of text

    Read the full thread on Reddit

  3. Screenshot of a post in r/asknetsec titled "Securing AI workloads in the data center, what firewall architecture actually works?" with 38 upvotes
    Upvotes
    38
    Comments
    9
    Posted
    Sep 3, 2026

    Why it worked

    • Asks the community a question instead of announcing something
    • Short paragraphs rather than one block of text

    Read the full thread on Reddit

  4. Screenshot of a post in r/asknetsec titled "Why did browser vendors move away from visual EV SSL indicators in the address bar" with 36 upvotes
    Upvotes
    36
    Comments
    19
    Posted
    Aug 30, 2026

    Why it worked

    • Kept short enough to read in one pass

    Read the full thread on Reddit

  5. Screenshot of a post in r/asknetsec titled "[iOS] Unnamed binary (UUID only, no path/signature) loaded inside the TikTok process in iOS analytics logs —…" with 35 upvotes
    Upvotes
    35
    Comments
    9
    Posted
    Sep 11, 2026

    Why it worked

    • Asks the community a question instead of announcing something
    • Short paragraphs rather than one block of text

    Read the full thread on Reddit

  6. Screenshot of a post in r/asknetsec titled "Which email security platform is best suited for a financial services company?" with 34 upvotes
    Upvotes
    34
    Comments
    18
    Posted
    Aug 24, 2026

    Why it worked

    • Asks the community a question instead of announcing something
    • Short paragraphs rather than one block of text

    Read the full thread on Reddit

  7. Screenshot of a post in r/asknetsec titled "Will AI make the existing network attack surface much harder to defend?" with 32 upvotes
    Upvotes
    32
    Comments
    20
    Posted
    Sep 2, 2026

    Why it worked

    • Asks the community a question instead of announcing something
    • Broken into a scannable list
    • Short paragraphs rather than one block of text

    Read the full thread on Reddit

  8. Screenshot of a post in r/asknetsec titled "How are you producing evidence for network and access controls during cyber insurance renewals?" with 31 upvotes
    Upvotes
    31
    Comments
    27
    Posted
    Aug 24, 2026

    Why it worked

    • Asks the community a question instead of announcing something
    • Short paragraphs rather than one block of text

    Read the full thread on Reddit

  9. Screenshot of a post in r/asknetsec titled "How are you handling credentials for AI agents that SSH/WinRM into real infrastructure?" with 28 upvotes
    Upvotes
    28
    Comments
    17
    Posted
    Sep 11, 2026

    Why it worked

    • Asks the community a question instead of announcing something
    • Short paragraphs rather than one block of text

    Read the full thread on Reddit

  10. Screenshot of a post in r/asknetsec titled "Third-party vendor breach scenario, how do you tabletop something you don't control?" with 28 upvotes
    Upvotes
    28
    Comments
    14
    Posted
    Sep 3, 2026

    Why it worked

    • Asks the community a question instead of announcing something

    Read the full thread on Reddit

What r/AskNetsec Is For

This community is for people passionate about security to ask and answer technical questions. The description says it is dedicated to those passionate about security, and the rules clarify that questions should relate to information security in an enterprise, large organization, or SOHO context. It is a question and answer space, not a discussion board or a place for sharing content.

Rules That Matter Before Posting

The rule named 'All submissions must be in the form of a question' is the first gate. Your post has to be a specific, answerable question, not a request for vague feedback or thoughts. The rule named 'All submissions must be relevant to information security' keeps the scope to enterprise, large organization, or SOHO contexts. The rule named 'No low effort questions' demands technical detail like operating systems, patch levels, and troubleshooting steps. The rule named 'Don't spam or excessively showcase your own content. No referral or affiliate links' is the one that determines whether a marketing-adjacent post survives. It allows you to respond if someone asks about your product, but you must clearly identify yourself as a representative.

What To Post

A good post here is a specific, answerable technical question about enterprise or SOHO security with enough detail that someone can actually help you. Include your operating system, application patch level, and any troubleshooting you have already tried. If you are a founder and someone asks a question about your product, you may respond as long as you clearly identify yourself as a representative of your organization. The safest path is to participate as a practitioner first, answering questions in your area of expertise, and only mention your product when someone specifically asks about it.

What To Avoid

Avoid anything that violates the rule named 'No questions about Career Advice, homework, or beginner questions.' Do not post about password managers, which the rule named 'No questions about password managers' sends elsewhere. Do not post about personal devices being hacked, as the rule named 'No posts asking about being hacked' covers suspicious links, weird phone behavior, and cyber stalking. Avoid low effort posts that lack technical detail, since the rule named 'No low effort posts' requires operating systems, patch levels, and troubleshooting context. Do not spam or shill, and never include referral or affiliate links.

Use Rankhog before posting in r/AskNetsec

Want the version that does not run out? Subscribers get unlimited tool runs and more careful checks before posting.

Get my free Reddit SEO audit

Start your 3-day free trial. Card required. $99/month after trial. Next, connect a verified Reddit account; no strategy starts until you explicitly start Rankhog.

Common questions about r/AskNetsec

Can I promote my security product here?

Only if someone asks a specific question about your product and you clearly identify yourself as a representative of that organization.

Can I share a blog post or video about my security tool?

No, referral and affiliate links are not allowed, and posting low quality blogs, vlogs, or YouTube videos is considered spam.

Can I ask for career advice in security?

No, questions about career advice, what cert to get, and how to get started should be posted to other subreddits.

Can I post about a suspected hack on my personal device?

No, questions about being hacked on a personal computer or phone are not allowed here.

What technical details should I include in my question?

Include operating systems, application patch level, previous troubleshooting steps, and any other technical context you can provide.

Related subreddit guides