oss-sec mailing list archives
Re: snowflakedb security contacts
From: Christian Heinrich <christian.heinrich () cmlh id au>
Date: Tue, 26 Jul 2022 09:21:37 +0930
Seth, On Tue, 26 Jul 2022 at 08:00, Seth Arnold <seth.arnold () canonical com> wrote:
HackerOne feels a bit formal for me: not everyone reporting issues is out for bug bounties and so on -- but having seen more than my fair share of "all your source code is public" reports, I'm also sympathetic.
Direct contact is usually banned by https://www.hackerone.com/policies/code-of-conduct "Only contact security teams through approved channels Only use approved communication channels. Unless the program has intentionally provided a contact method to the Finder, contacting security teams “out-of-band” is a violation of this CoC. Approved communication channels will be outlined within the program policy page or otherwise notified by the customer, should nothing be specifically mentioned, all Finders must assume that the HackerOne platform is the only approved channel." -- Regards, Christian Heinrich http://cmlh.id.au/contact
Current thread:
- snowflakedb security contacts Seth Arnold (Jul 18)
- Re: snowflakedb security contacts Roxana Bradescu (Jul 24)
- Re: snowflakedb security contacts Seth Arnold (Jul 25)
- Re: snowflakedb security contacts Christian Heinrich (Jul 26)
- Re: snowflakedb security contacts Seth Arnold (Jul 25)
- Re: snowflakedb security contacts Roxana Bradescu (Jul 24)