Closed kkarhan closed 1 week ago
We don't use GPG in the team in a widespread manner so it'd have created more friction for researchers to reach out ot us.
Please reach out via plaintext email and we'll be happy to move the conversation to a more secure channel if need be.
For security reasons alone, I do expect basic standards like security.txt
aka. RFC9116 to be implemented.
If you need help getting said security infrastructure setup I'm open for offers.
Using insecure channels to communicate is inherently bad and setting up PGP is trivial, as it deploying, updating and redistributing said public and private keys.
Also please reopen the issue!
Do you have an actual report to make?
We have been coordinating with security people for years, there are ways other than PGP.
I find it ironic you chose to ignore our SECURITY.md file which you did read since you mentioned it in your initial message.
If you actually have a report to make please follow what's outlined there.
As a matter of security, I'll not communicate anything related to security through insecure channels - period!
There is no excuse for not having a keypair for that at hand!
If you need help with setting it up (among multiple developers) I'm open for that.
As a matter of security, I'll not communicate anything related to security through insecure channels - period!
Then I'm afraid this conversation is over.
You seem to be more interested in satisfying your own needs than to working with us in disclosing security problems.
If you want to collaborate with us, please read SECURITY.md and get in touch through one of the listed ways, a GH issue is not one of them.
What happened?
The
SECURITY.md
file does not contain a Public Key for secure communications.Fix:
Please add a PGP Pubkey in ASCII Armoured format like:
and Fingerprint to it.
Platform
Browser / app / sdk version
Firefox 132.0.1 (amd64)
Relevant log output
No response
Reproducibility
More details?
This is security-related, abeit not a security incident, but may inconvenience responsible disclosure.