Archived
Add Security Policy #1001
Dismiss Review
Are you sure you want to dismiss this review?
Labels
Clear labels
:mag:🤖 Search Engines
approved
dependencies
duplicate
feedback wanted
high priority
I2P
iOS
low priority
OS
Self-contained networks
Social media
stale
streaming
todo
Tor
WIP
wontfix
XMPP
[m]
₿ cryptocurrency
ℹ️ help wanted
↔️ file sharing
⚙️ web extensions
✨ enhancement
❌ software removal
💬 discussion
🤖 Android
🐛 bug
💢 conflicting
📝 correction
🆘 critical
📧 email
🔒 file encryption
📁 file storage
🦊 Firefox
💻 hardware
🌐 hosting
🏠 housekeeping
🔐 password managers
🧰 productivity tools
🔎 research required
🌐 Social News Aggregators
🆕 software suggestion
👥 team chat
🔒 VPN
🌐 website issue
🚫 Windows
👁️ browsers
🖊️ digital notebooks
🗄️ DNS
🗨️ instant messaging (im)
🇦🇶 translations
approved, waiting for a PR
Pull requests that update a dependency file
The Invisible Internet Project (I2P)
Operating Systems
A label for stalebot if it gets added
Anything related to media streaming.
Anything covering the Tor network
active work in progress, do not merge or PR (yet)!
Issues or bugs that will not be fixed and/or do not have significant impact on the project.
Extensible Messaging and Presence Protocol
Matrix protocol
Browser Extension related issues
Correction of content on the website
Firefox & forks, about:config etc.
Anything primarily related to site cleanup.
Virtual Private Network
*Technical* issues with the website.
Domain Name System
Anything covering a translated version of the site
No labels
feedback wanted
Milestone
No items
No Milestone
No due date set.
Dependencies
No dependencies set.
Reference: privacyguides/privacytools.io#1001
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
As recommended in #988:
This sounds good to me. I added some basic instructions to a security policy file, do you think this is enough or well-constructed? Let me know if anything should be added @beardog108.
Closes #988
Deploy preview for privacytools-io ready!
Built with commit
ad344be456https://deploy-preview-1001--privacytools-io.netlify.com
Thanks for adding. Looks pretty good, but i'd clarify that user & admin accounts not owned by the tester are out of scope as well.
@@ -0,0 +20,4 @@* Reports against infrastructure outside our control* User or admin accounts not owned by the tester## Disclosure PolicyThis does not seem to include if users will be informed in case data is leaked.
My understanding is that social.privacytools.io and other services collect information like email.
What happens if this information gets stolen? How would users be informed?
@@ -0,0 +20,4 @@* Reports against infrastructure outside our control* User or admin accounts not owned by the tester## Disclosure PolicyAdded info to
ad344be