Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 4 additions & 7 deletions VULNERABILITY_RESPONSE_PROCESS.md
Original file line number Diff line number Diff line change
Expand Up @@ -24,30 +24,27 @@

## I. Points of contact for security issues

**Please, CC all points of contact if you decide to use email instead of HackerOne**
**Please, CC all points of contact if you decide to use another method instead of HackerOne**

Available points of contact:
```
luigi1111 [at] getmonero.org
PGP fingerprint = 8777 AB8F 778E E894 87A2 F8E7 F4AC A018 3641 E010
moneromooo on irc.libera.chat
PGP fingerprint = 48B0 8161 FBDA DFE3 93AD FC3E 686F 0745 4D6C EFC3
If pasting GPG encrypted data, use paste.debian.net or paste.ubuntu.com
as these don't blackball Tor via Cloudflare.
OTR: DA3DD149 6DEF8EF1 941FB6BC 4FD8DFCC 7EF36E39 on irc.libera.chat
OTR: 6C7966BB 72E42F33 E1A3F137 2133AC39 D343514A on irc.freenode.net
```

## II. Security response team
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

There are more people that have access to the HackerOne, so how exactly is security reponse team defined?

Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I would assume anyone who have access to the report without being invited.

Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

In this case I would keep luigi. serhack also has access, though I'm not sure how active he is currently.

Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ngl I never heard of serhack, I'll just keep luigi

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Only seen them on Reddit before

Copy link

@nahuhh nahuhh Apr 28, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Everyone's heard of serhack 😅

among other things, is the author of Mastering Monero

Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Everyone's heard of serhack 😅

among other things, is the author of Mastering Monero

ah alright lol. i guess he can be listed


- luigi1111
- moneromooo
- selsta

## III. Incident response

1. Researcher submits report via one or both of two methods:
- a. PGP encrypted Email (use the appropriate fingerprints [listed in section I](#i-points-of-contact-for-security-issues) or as included in the Monero repo in `utils/gpg_keys/`)
- a. PGP encrypted pastebin or Email (use the appropriate fingerprints [listed in section I](#i-points-of-contact-for-security-issues) or as included in the Monero repo in `utils/gpg_keys/`)
- b. [HackerOne](https://hackerone.com/monero)

2. Response Team designates a Response Manager who is in charge of the particular report based on availability and/or knowledge-set
Expand Down