[prev in list] [next in list] [prev in thread] [next in thread] 

List:       oss-security
Subject:    Re: [oss-security] snowflakedb security contacts
From:       Christian Heinrich <christian.heinrich () cmlh ! id ! au>
Date:       2022-07-26 0:03:37
Message-ID: CAGKxTUSFnV50gJvJsoWb2TJ6_44hXrt1F-iKGirS_SdBigGYFA () mail ! gmail ! com
[Download RAW message or body]

Seth,

On Tue, 26 Jul 2022 at 08:00, Seth Arnold <seth.arnold@canonical.com> wrote:
> HackerOne feels a bit formal for me: not everyone reporting issues is out
> for bug bounties and so on -- but having seen more than my fair share of
> "all your source code is public" reports, I'm also sympathetic.

Direct contact is usually banned by
https://www.hackerone.com/policies/code-of-conduct

"Only contact security teams through approved channels

Only use approved communication channels. Unless the program has
intentionally provided a contact method to the Finder, contacting
security teams "out-of-band" is a violation of this CoC. Approved
communication channels will be outlined within the program policy page
or otherwise notified by the customer, should nothing be specifically
mentioned, all Finders must assume that the HackerOne platform is the
only approved channel."


-- 
Regards,
Christian Heinrich

http://cmlh.id.au/contact
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic