Skip to content

Security: appsoftwareltd/etherpk-client

SECURITY.md

Security

Report a vulnerability privately through GitHub: on this repository's Security tab, select Report a vulnerability. Do not open a public issue.

Include the version you tested, the steps to reproduce, and what an attacker gains. EtherPK's Sync Server is designed never to read graph content, so a way to recover plaintext notes, keys or a Recovery Code from anything the server stores or relays is in scope and the most serious class of report. So is a way for the server to make a Client accept keys it did not check: a forged invite, key write or copy of a graph's key, a changed key for someone the user has verified, or a device approval that does not show different codes on the two screens. A way to run script in the Client's page past its Content Security Policy and Trusted Types is also serious, because the page holds the keys.

There aren't any published security advisories