Date: Tue, 26 Jul 2022 09:21:37 +0930 From: Christian Heinrich <christian.heinrich@...h.id.au> To: oss-security@...ts.openwall.com Subject: Re: snowflakedb security contacts Seth, On Tue, 26 Jul 2022 at 08:00, Seth Arnold <seth.arnold@...onical.com> wrote: > HackerOne feels a bit formal for me: not everyone reporting issues is out > for bug bounties and so on -- but having seen more than my fair share of > "all your source code is public" reports, I'm also sympathetic. Direct contact is usually banned by https://www.hackerone.com/policies/code-of-conduct "Only contact security teams through approved channels Only use approved communication channels. Unless the program has intentionally provided a contact method to the Finder, contacting security teams “out-of-band” is a violation of this CoC. Approved communication channels will be outlined within the program policy page or otherwise notified by the customer, should nothing be specifically mentioned, all Finders must assume that the HackerOne platform is the only approved channel." -- Regards, Christian Heinrich http://cmlh.id.au/contact
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.