Just as important as discovering security flaws is reporting the findings so that users can protect themselves and vendors can repair their products. Public disclosure of security information enables informed consumer choice and inspires vendors to be truthful about flaws, repair vulnerabilities, and build more secure products. Disclosure and peer review advances the state of the art in security. Researchers can figure out where new technologies need to be developed, and the information can help policymakers understand where problems tend to occur.
On the other hand, vulnerability information can give attackers who were not otherwise sophisticated enough to find the problem on their own the very information they need to exploit a security hole in a computer or system and cause harm. Therefore we ask that you privately report the vulnerability to Urban.io before public disclosure.
Send an email to [email protected] using the GPG key located here, with information about the vulnerability and detailed steps on how to replicate it. Submissions that include detailed information on how to fix the corresponding vulnerability are more likely to receive more valuable rewards.
If you do not want to be publicly thanked by Urban.io by publishing on our Website (or elsewhere), please let us know that you want your submission to be confidential in your report email. We can/will provide rewards for confidential submissions.
We are also happy to accept anonymous vulnerability reports, but of course, we can’t send you our thanks if you report a vulnerability anonymously.
We will make every effort to respond to valid reports within seven business days.
The validity of a vulnerability will be judged at the sole discretion of Urban.io.