| Version | Supported |
|---|---|
| 0.1.x | ✅ |
| < 0.1 | ❌ |
We take the security of Audio Ninja seriously. If you believe you have found a security vulnerability, please report it to us responsibly.
Please DO NOT file a public issue. Instead:
- Email security details to: [INSERT EMAIL ADDRESS]
- Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if available)
- Acknowledgment: Within 48 hours of your report
- Initial Assessment: Within 7 days
- Status Updates: Every 7 days until resolution
- Disclosure: Coordinated disclosure after fix is available
When using Audio Ninja:
-
Network Security
- Use VLANs to isolate audio traffic
- Enable encryption for sensitive environments
- Validate speaker identity before pairing
-
Access Control
- Restrict BLE pairing to authorized devices
- Use secure WiFi passwords
- Implement firewall rules for UDP/RTP ports
-
Updates
- Keep dependencies up to date
- Monitor security advisories
- Test updates in non-production environments first
-
Configuration
- Use strong authentication for control APIs
- Limit network exposure of management interfaces
- Validate user inputs
-
Network Transport
- UDP/RTP traffic is unencrypted by default
- Consider IPsec or VPN for sensitive audio
- Packet injection could affect audio quality
-
BLE Control
- Pairing uses standard BLE security
- Physical proximity required for initial pairing
- Monitor for unauthorized connection attempts
-
Room Calibration
- Calibration sweeps can be loud
- Verify speaker configuration before measurement
- Store calibration data securely
- Security issues will be disclosed publicly after a fix is available
- Credit will be given to reporters (unless anonymity is requested)
- CVE IDs will be obtained for significant vulnerabilities
We appreciate responsible disclosure. Contributors who report valid security issues will be acknowledged here (with permission).
Thank you for helping keep Audio Ninja and our users safe!