Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Tue, 26 Jul 2022 09:21:37 +0930
From: Christian Heinrich <christian.heinrich@...h.id.au>
To: oss-security@...ts.openwall.com
Subject: Re: snowflakedb security contacts

Seth,

On Tue, 26 Jul 2022 at 08:00, Seth Arnold <seth.arnold@...onical.com> wrote:
> HackerOne feels a bit formal for me: not everyone reporting issues is out
> for bug bounties and so on -- but having seen more than my fair share of
> "all your source code is public" reports, I'm also sympathetic.

Direct contact is usually banned by
https://www.hackerone.com/policies/code-of-conduct

"Only contact security teams through approved channels

Only use approved communication channels. Unless the program has
intentionally provided a contact method to the Finder, contacting
security teams “out-of-band” is a violation of this CoC. Approved
communication channels will be outlined within the program policy page
or otherwise notified by the customer, should nothing be specifically
mentioned, all Finders must assume that the HackerOne platform is the
only approved channel."


-- 
Regards,
Christian Heinrich

http://cmlh.id.au/contact

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.