Commit graph

30 commits

Author SHA1 Message Date
anonimal
632f4e29d8
VRP: make explicit the requirement for hash rate attack 2020-01-17 23:10:14 +00:00
anonimal
755ddd94d9
VRP: update paste links
pastebin.mozilla.org is permanently offline. fpaste.org redirects to
paste.centos.org
2020-01-17 22:20:57 +00:00
anonimal
1cadbcdcd7
VRP: remove Kovri + update points of contact 2020-01-17 22:17:29 +00:00
luigi1111
dca48a12c7
Merge pull request #313 from anonimal/VRP-public-platform
VRP: redefine public communications platform
2019-04-30 16:09:32 -05:00
anonimal
a61b8818ef
VRP: redefine public communications platform
As we agreed to (the VRP team).
2019-03-09 00:56:04 +00:00
anonimal
de46de83ee
VRP: specify type of DoS in relation to reward
As we agreed to (the VRP team).
2019-03-09 00:31:04 +00:00
anonimal
dc2b463b78
VRP: apply preamble to kovri beta
As agreed to on IRC.
2018-06-29 06:24:08 +00:00
anonimal
378c236532
VRP: reiterate that code impl includes master branch 2018-06-29 06:24:08 +00:00
luigi1111
19df3b6588
Merge pull request #215 from anonimal/VRP
VRP: add note for monero 50%+ hash rate attacks
2018-06-13 12:50:08 -05:00
binaryFate
15215791f3 Specify explicitly that XMR bounties are paid from community, donated funds 2018-05-02 01:48:06 -04:00
anonimal
4f63f0c637
VRP: add note for monero 50%+ hash rate attacks 2018-05-01 00:08:18 +00:00
anonimal
8be20cd589
VRP: add bounty eligibility to preamble 2018-03-14 20:10:12 +00:00
luigi1111
2a4b31b5ae
Merge pull request #187 from anonimal/email
VRP: update kovri email contact
2018-03-09 14:14:29 -05:00
luigi1111
5bc9755760
Merge pull request #185 from moneromooo-monero/mooo
Remove my email address, I didn't add it and I check it less than mon…
2018-03-09 14:14:05 -05:00
moneromooo-monero
cbcc3db4bb
Remove my email address, I didn't add it and I check it less than monthly
Use IRC instead, I check that more than daily.
Also add suitable paste sites and OTR fingerprint.
2018-03-02 22:31:20 +00:00
anonimal
1ae8032c1e
VRP: update kovri email contact 2018-03-01 05:12:15 +00:00
anonimal
33e2e087a2
VRP: researcher will receive name credit by default 2018-02-21 01:24:48 +00:00
anonimal
03ff9a601b
VRP: clarify definition of LOW severity vulnerability 2018-02-15 08:46:11 +00:00
luigi1111
9932077f6a
Merge pull request #163 from leonklingele/vulnerability-prefer-mail
Vulnerability response: Prefer to use Email + GPG
2018-01-26 14:24:53 -05:00
anonimal
f01d36de29
VRP: clarify that both code *and* research are applicable 2018-01-25 17:51:08 +00:00
anonimal
5a39ee5991
VRP: specify that PGP key is a PGP key in preamble 2018-01-25 17:42:13 +00:00
anonimal
7f4975e801
VRP: formatting fix to preamble 2018-01-25 17:37:08 +00:00
anonimal
9f147306e4
VRP: re-org the preamble, create kovri section 2018-01-25 17:33:23 +00:00
Leon Klingele
cb2a030c86
VRP: Suggest to use PGP encrypted email over plain text email 2018-01-21 15:08:15 +01:00
xmr-eric
103d98fbb5
VULNERABILITY_RESPONSE_PROCESS.md: Better headings
See: https://github.com/monero-project/monero/pull/2881

This proposal seeks to put the heading capitalization policy inline with the main Monero readme. Capitalizing every single word in a heading begins to feel redundant and cumbersome when headings become long (and many are indeed quite long). A much better practice is capitalizing just the initial word.
2017-12-05 00:18:26 -05:00
anonimal
611f2461a6
VRP: clarify PoC submission requirement 2017-12-02 00:32:57 +00:00
anonimal
93abfa7280
VRP: add new line for defining bug severity 2017-11-30 20:51:36 +00:00
anonimal
4d7b2d8629
VRP: add section Bounty Distribution 2017-11-30 20:51:36 +00:00
anonimal
10d7616b90
VRP: add new caveats to Preamble 2017-11-29 08:49:16 +00:00
anonimal
33fd336d69
The Monero Project: create single-policy VRP
We currently have policies on a per-repo basis. A single-policy VRP
eases maintainability while minimizing confusion for researchers.
2017-09-07 03:12:52 +00:00