ru — showing the en original.Reporting a vulnerability
If you have found a security problem in LibreTimes, tell us privately at security@libretimes.io before telling anyone else.
Do not open a public issue for a security report. Do not post it publicly while it is unfixed.
What to include
- What the problem is, and what an attacker could do with it
- Steps to reproduce it, in enough detail that we can follow them
- Anything relevant about your setup: browser, account state, timing
- How you would like to be credited, if we fix it
A working proof of concept helps. A vulnerability scanner's output, pasted without interpretation, generally does not.
What happens next
We will confirm we have your report, tell you whether we consider it a vulnerability, and let you know when it is fixed. We are a small team, so please allow a few working days, and send a reminder if you have heard nothing.
Once it is fixed, you are welcome to write about it publicly. If you would like to publish sooner, tell us and we will agree a date rather than argue about it afterwards.
Testing: what is fine, and what is not
You may probe your own account, and you may test against the public site to the extent needed to demonstrate a problem.
You must not:
- Access, download, or retain other people's personal data. If you can reach it, stop, and describe what you could reach instead of collecting it.
- Extract or publish credentials, keys, or internal configuration.
- Degrade the service for other people. No load testing, no denial of service, no automated scanning heavy enough to hurt.
- Modify or delete data that is not yours.
- Use social engineering, phishing, or physical access against anyone.
The line is not about intent. Looking for a flaw is fine; taking other people's data is unlawful in most countries whatever you meant by it, and we will treat it that way.
Stay inside these rules and we will treat your report as good-faith research and will not pursue you over it.
Recognition
We do not run a funded bug bounty. We are a small project and cannot promise payment.
What we can offer, depending on the report:
- Public credit on a security acknowledgements page, if you want it
- A payment, when we have the funds and the finding warrants it – offered at our discretion, never guaranteed in advance
- Our agreement to your writing the finding up publicly once it is fixed
If you need a guaranteed payout, this is not that programme, and we would rather say so plainly than imply otherwise.
Scope
The live LibreTimes site and its supporting hosts are in scope.
Out of scope: anything you find only by breaking the testing rules above, reports that amount to missing best-practice headers with no demonstrated impact, and findings in third-party services we do not run.
Not a security problem?
For ordinary bugs, see Report a problem.