jitsi / jitsi-meet

Jitsi Meet - Secure, Simple and Scalable Video Conferences that you use as a standalone app or embed in your web application.
https://jitsi.org/meet
Apache License 2.0
23.27k stars 6.76k forks source link

Bug: Missing PGP Pubkey in SECURITY.md #15287

Closed kkarhan closed 1 week ago

kkarhan commented 1 week ago

What happened?

The SECURITY.md file does not contain a Public Key for secure communications.

Fix:

Platform

Browser / app / sdk version

Firefox 132.0.1 (amd64)

Relevant log output

No response

Reproducibility

More details?

This is security-related, abeit not a security incident, but may inconvenience responsible disclosure.

saghul commented 1 week ago

We don't use GPG in the team in a widespread manner so it'd have created more friction for researchers to reach out ot us.

Please reach out via plaintext email and we'll be happy to move the conversation to a more secure channel if need be.

kkarhan commented 1 week ago

For security reasons alone, I do expect basic standards like security.txt aka. RFC9116 to be implemented.

Also please reopen the issue!

saghul commented 1 week ago

Do you have an actual report to make?

We have been coordinating with security people for years, there are ways other than PGP.

I find it ironic you chose to ignore our SECURITY.md file which you did read since you mentioned it in your initial message.

If you actually have a report to make please follow what's outlined there.

kkarhan commented 1 day ago

As a matter of security, I'll not communicate anything related to security through insecure channels - period!

There is no excuse for not having a keypair for that at hand!

If you need help with setting it up (among multiple developers) I'm open for that.

saghul commented 1 day ago

As a matter of security, I'll not communicate anything related to security through insecure channels - period!

Then I'm afraid this conversation is over.

You seem to be more interested in satisfying your own needs than to working with us in disclosing security problems.

If you want to collaborate with us, please read SECURITY.md and get in touch through one of the listed ways, a GH issue is not one of them.