 | TurboSFV - Security |
| Overview |
|
TurboSFV is generally coded in a secure manner: Means no risky operations in the program code, third party libraries
as less as possible and a proper testing of new functionality before releasing. However, coders are humans (at least here)
and humans can make mistakes, so there is no guarantee for a 100% error free software. Therefore, an error or a weakness
could end up in a security vulnerability, which should be fixed as soon as possible.
|
|
Thus, similar to reporting errors, we encourage users to report us also possible vulnerabilities.
|
| Vulnerability Disclosure Policy |
| Contact details |
|
A possible security vulnerability can be reported to
|
E-Mail:
|
|
Regarding this kind of sensitive information, we support and prefer an encrypted communication, so here is
our public PGP Key.
|
Vulnerability reports will be accepted for a current version of TurboSFV, but not for third party software. Please
include in the report the following information:
- TurboSFV version number
- Underlying operating system including the build number.
- Detailed description of the possible weakness and its exploitation and how to reproduce it.
- A possible solution.
|
| Our response |
|
After receiving your vulnerability report, we will analyse the weakness and assess the possible exploitation. Please
give us sufficient time for that and reserve yourself a bit time for the case, that we need your help for a deeper
analysis. We will send you a first response within five working days, and keep you updated about the progress.
|
|
In case of a confirmed vulnerability, we will then develop a fix and make it available for our customers. In the
meantime, if required, we will also share appropriate information about the vulnerability with a corresponding
reporting platform, to ensure that the incident is properly communicated.
|
|
Once the fix is ready and our customers had the opportunity to patch, we will publicly disclose the vulnerability.
If you like, as acknowledgment for your contribution, we can name you as the researcher, who kindly helped us to
find and fix the issue. Otherwise, we keep your personal data from our conversation as confidential, as stated in our
privacy policy.
In any case, you will get a final response, in which the vulnerability report will be closed.
|
|
Thank you in advance for helping us!
|
| Security Advisories |
|
Actually no security advisory hints available.
|
|
|
|
|
|