oss-sec mailing list archives

Re: snowflakedb security contacts


From: Christian Heinrich <christian.heinrich () cmlh id au>
Date: Tue, 26 Jul 2022 09:21:37 +0930

Seth,

On Tue, 26 Jul 2022 at 08:00, Seth Arnold <seth.arnold () canonical com> wrote:
HackerOne feels a bit formal for me: not everyone reporting issues is out
for bug bounties and so on -- but having seen more than my fair share of
"all your source code is public" reports, I'm also sympathetic.

Direct contact is usually banned by
https://www.hackerone.com/policies/code-of-conduct

"Only contact security teams through approved channels

Only use approved communication channels. Unless the program has
intentionally provided a contact method to the Finder, contacting
security teams “out-of-band” is a violation of this CoC. Approved
communication channels will be outlined within the program policy page
or otherwise notified by the customer, should nothing be specifically
mentioned, all Finders must assume that the HackerOne platform is the
only approved channel."


-- 
Regards,
Christian Heinrich

http://cmlh.id.au/contact


Current thread: