ehn-dcc-development / eu-dcc-hcert-spec

Electronic Health Certificates Specification
363 stars 40 forks source link

Best way to report security issues? #81

Closed oc-ja closed 3 years ago

oc-ja commented 3 years ago

Hello everyone,

if I have found a security risk, which I think would be best addressed at the specification/requirements-level, whom should I contact and how?

I should note, that I'm not part of any development team currently implementing the specification, so I don't have any internal contacts.

Thank you!

Regards,

Jan

jschlyter commented 3 years ago

Please email me, jakob(at)kirei.se

chris2286266 commented 3 years ago

Hello Jan,

maybe you enlighten us all and use this channel to tell us about your findings.

THX

jschlyter commented 3 years ago

I will create an issue once analyzed.

asitplus-pteufl commented 3 years ago

@oc-ja can you send the information to peter.teufl(at)a-sit.at as well, if this is urgent, we need to analyze this as well, all the things are going into final tests/production (AT) anything related to security would need to be known ASAP. Thx