Skip to content

Latest commit

History

History
93 lines (56 loc) 路 5.19 KB

File metadata and controls

93 lines (56 loc) 路 5.19 KB

Responsible Disclosure Policy

Flow was built from the ground up with security in mind. Our code, infrastructure, and development methodology helps us keep our users safe.

We really appreciate the community's help. Responsible disclosure of vulnerabilities helps to maintain the security and privacy of everyone.

If you care about making a difference, please follow the guidelines below.

Guidelines聽For聽Responsible聽Disclosure

We聽ask聽that聽all聽researchers聽adhere聽to聽these聽guidelines.

Rules聽of聽Engagement

  • Make聽every聽effort聽to聽avoid聽unauthorized聽access,聽use,聽and聽disclosure聽of聽personal聽information.
  • Avoid聽actions聽which聽could聽impact聽user聽experience,聽disrupt聽production聽systems,聽change,聽or聽destroy聽data聽during聽security聽testing.
  • Don鈥檛聽perform聽any聽attack聽that聽is聽intended聽to聽cause聽Denial聽of聽Service聽to聽the聽network,聽hosts,聽or聽services聽on聽any聽port聽or聽using聽any聽protocol.
  • Use聽our聽provided聽communication聽channels聽to聽securely聽report聽vulnerability聽information聽to聽us.
  • Keep聽information聽about聽any聽bug聽or聽vulnerability聽you聽discover聽confidential聽between聽us聽until聽we聽publicly聽disclose聽it.
  • Please聽don鈥檛聽use聽scanners聽to聽crawl聽us聽and聽hammer聽endpoints.聽They鈥檙e聽noisy聽and聽we聽already聽do聽this.聽If聽you聽find聽anything聽this聽way,聽we聽have聽likely聽already聽identified聽it.
  • Never聽attempt聽non-technical聽attacks聽such聽as聽social聽engineering,聽phishing,聽or聽physical聽attacks聽against聽our聽employees,聽users,聽or聽infrastructure.

In聽Scope URIs

Be聽careful聽that聽you're聽looking聽at聽domains聽and聽systems聽that聽belong聽to聽us聽and聽not聽someone聽else.聽When聽in聽doubt,聽please ask us.聽Maybe聽ask us anyway.

Bottom聽line,聽we聽suggest聽that聽you聽limit聽your聽testing聽to聽infrastructure that is clearly聽ours.

Out聽of聽Scope URIs

The聽following聽base聽URIs聽are聽explicitly聽out聽of聽scope:

  • None

Things聽Not聽To聽Do

In聽the聽interests聽of聽your聽safety,聽our聽safety,聽and聽for聽our聽customers,聽the聽following聽test聽types聽are聽prohibited:

  • Physical聽testing聽such聽as聽office聽and聽data-centre聽access聽(e.g.聽open聽doors,聽tailgating,聽card聽reader聽attacks,聽physically聽destructive聽testing)
  • Social聽engineering聽(e.g.聽phishing,聽vishing)
  • Testing聽of聽applications聽or聽systems聽NOT聽covered聽by聽the聽鈥業n聽Scope鈥櫬爏ection,聽or聽that聽are聽explicitly聽out聽of聽scope.
  • Network聽level聽Denial聽of聽Service聽(DoS/DDoS)聽attacks

Sensitive聽Data

In聽the聽interests聽of聽protecting聽privacy,聽we聽never聽want聽to聽receive:

  • Personally聽identifiable聽information聽(PII)
  • Payment聽card聽(e.g.聽credit聽card)聽data
  • Financial聽information聽(e.g.聽bank聽records)
  • Health聽or聽medical聽information
  • Accessed聽or聽cracked聽credentials聽in聽cleartext

Our聽Commitment聽To聽You

If聽you聽follow聽these聽guidelines聽when聽researching聽and聽reporting聽an聽issue聽to聽us,聽we聽commit聽to:

  • Not聽send聽lawyers聽after聽you聽related聽to聽your聽research聽under聽this聽policy;
  • Work聽with聽you聽to聽understand聽and聽resolve聽any聽issues聽within聽a聽reasonable聽timeframe,聽including聽an聽initial聽confirmation聽of聽your聽report聽within聽72聽hours聽of聽submission;聽and
  • At聽a聽minimum,聽we聽will聽recognize聽your聽contribution聽in聽our聽Disclosure聽Acknowledgements聽if聽you聽are聽the聽first聽to聽report聽the聽issue聽and聽we聽make聽a聽code聽or聽configuration聽change聽based聽on聽the聽issue.

Disclosure聽Acknowledgements

We're happy to acknowledge contributors. Security acknowledgements can be found here.

Rewards

We run closed bug bounty programs, but beyond that we also pay out rewards, once per eligible bug, to the first responsibly disclosing third party. Rewards are based on the seriousness of the bug, but the minimum is $100 and we have and are willing to pay $5,000 or more at our sole discretion.

Elligibility

To qualify, the bug must fall within our scope and rules and meet the following criteria:

  1. Previously unknown - When reported, we must not have already known of the issue, either by internal discovery or separate disclosure.
  2. Material impact - Demonstrable exploitability where, if exploited, the bug would materially affect the confidentiality, integrity, or availability of our services.
  3. Requires action - The bug requires some mitigation. It is both valid and actionable.

Reporting聽Security聽Findings聽To聽Us

Reports are welcome! Please definitely reach out to us if you have a security concern.

We prefer you to please send us an email: security@onflow.org

Note: If you believe you may have found a security vulnerability in our open source repos, to be on the safe side, do NOT open a public issue.

We聽encourage聽you聽to聽encrypt聽the聽information聽you聽send聽us聽using聽our聽PGP聽key at keys.openpgp.org/security@onflow.org

Please聽include聽the聽following聽details聽with聽your聽report:

  • A聽description聽of聽the聽location聽and聽potential聽impact聽of聽the聽finding(s);
  • A聽detailed聽description聽of聽the聽steps聽required聽to聽reproduce聽the聽issue;聽and
  • Any聽POC聽scripts,聽screenshots,聽and聽compressed聽screen聽captures,聽where聽feasible.