Security
Posted in
Thank you for taking the time to help improve the security of this website.
If you believe you have discovered a security vulnerability, please report it responsibly. I appreciate reports that help identify genuine security issues and will investigate them as quickly as possible.
Reporting a vulnerability
Please send your report to [email protected].
To help reproduce and understand the issue, please include as much information as possible, such as:
- The affected URL or page.
- A description of the vulnerability.
- Steps to reproduce the issue.
- Any proof of concept, screenshots or sample requests.
- Your browser, operating system and any relevant software versions.
Responsible disclosure
Please do not publicly disclose the vulnerability until I have had a reasonable opportunity to investigate and, where appropriate, resolve the issue.
I will acknowledge receipt of your report and will make reasonable efforts to keep you informed of its progress.
Encryption
If you prefer to encrypt your report, you may use the OpenPGP key associated with my personal email address. The key is published on the usual public key servers and can also be obtained on request.
Scope
I do not operate a bug bounty programme. While I greatly appreciate responsible disclosure, I am unable to offer financial rewards for vulnerability reports.
Acknowledgements
With your permission, I would be happy to acknowledge your contribution after the issue has been resolved.
