Reporting a security issue.
The fastest path from "I have a GPU or ASIC" to "shares are landing" on the testnet demo. Five steps.
01 How to report
If you have found a security issue in any part of the stack, I would like to hear about it. Please report it privately rather than posting it publicly, so a fix can be in place before the details are widely known.
Email steven@getcrypto.co.in. If the issue is sensitive, you can encrypt your report to my GPG key, which is published on the /about page along with its fingerprint. A clear write-up in plain text is perfectly fine too — encryption is welcome, not required.
A good report includes:
- Steps to reproduce — enough detail for me to see the issue myself, ideally a minimal sequence.
- Impact — what the issue lets someone do, and which part of the stack is affected.
- Your contact details — so I can follow up with questions and let you know when it is resolved.
02 What happens next
Here is what you can expect after you report something:
- Acknowledge — I will confirm I have received your report.
- Investigate — I will look into it, reproduce it where I can, and come back to you if I need more detail.
- Coordinate — I will work on a fix and agree timing with you, with the aim of having it in place before any public disclosure. I will keep you posted on progress and credit you if you would like that.
03 Scope
In scope — issues affecting the security of:
- the website (getcrypto.co.in) and the operator dashboard,
- the wallet software,
- the pool and node software that makes up the stack.
Out of scope:
- Testnet coin value. Everything here runs on testnet and the coins have no monetary value, so reports framed around the worth of test units are not security issues.
- Volumetric denial of service. Reports that amount to “I can send a lot of traffic” are not in scope; please do not run load or stress tests against the live service.