CÔNG BỐ PHỐI HỢP
Chính sách công bố lỗ hổng
Chính sách xác định nghiên cứu bảo mật thiện chí, hoạt động bị cấm, xử lý bằng chứng nhạy cảm và công bố phối hợp.
01
Trong phạm vi
- quantumsafe.mobile-id.vn and explicitly listed demonstration endpoints.
- Published QuantumSafe product releases and pilot packages supplied for testing.
- API/documentation errors that create a security impact.
- Authentication, authorization, cryptographic misuse, injection, data exposure and supply-chain issues.
02
Ngoài phạm vi / bị cấm
- Denial-of-service, destructive or high-volume testing.
- Social engineering, phishing or physical intrusion.
- Accessing, retaining or modifying another party’s data.
- Persistence, lateral movement or credential harvesting.
- Testing production customers without written authorization.
- Publishing unredacted secrets or personal information.
03
Yêu cầu thiện chí
Use the minimum access necessary, stop when sensitive data is encountered, preserve evidence securely, allow reasonable remediation time and coordinate disclosure with PSIRT. Mobile-ID will evaluate safe-harbor language with legal counsel before production publication; this draft does not create a legal waiver.
04
Quy trình công bố
| Topic | Policy |
|---|---|
| Communication | Use the PSIRT tracking ID and agreed secure channel |
| Status updates | Provided based on severity and remediation complexity |
| CVE | Requested/assigned where applicable and approved |
| Public disclosure | Coordinated after mitigation or agreed deadline |
| Acknowledgment | Published only with researcher consent |
| Confidentiality | Reports and reporter data are access-controlled |
Tra cứu tự động
Công cụ bảo mật có thể sử dụng security.txt — RFC 9116. Người báo cáo nên sử dụng trang báo cáo lỗ hổng bảo mật.
