Conversation
…gger Level 2 escalated on "a repeat instance, or publishing something an attacker can act on immediately". Publishing vulnerability details is always something an attacker can act on, so that clause caught every case and separated nothing from level 1. A repeat instance is the trigger. Forfeiting the bounty on a report already submitted runs through Immunefi under their terms, so it is not ours to enforce. Future eligibility is. A warning leaves an earned bounty alone, a suspension makes reports during those 3 months ineligible, and a permanent block ends eligibility for good. Raised by Matt and Eric reviewing the security blog draft.
|
| **2. Suspension.** A repeat instance removes the reporter from any private | ||
| notification or pre-disclosure list for 3 months. We continue to accept and act |
There was a problem hiding this comment.
First-instance suspension is unclear. Level 2 now names only a repeat instance as its trigger, while the policy below says severity can determine the level even for a first instance. That leaves the response team and reporters without a clear rule for a serious first disclosure that warrants suspension but not a permanent block. Please clarify whether severity can trigger a first-instance suspension.
Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!
Two problems Matt and Eric found reading the blog draft.
Level 2 escalated on "publishing something an attacker can act on immediately", which is true of every disclosure, so it never distinguished anything from level 1.
Retroactively voiding a bounty on an already-submitted report is Immunefi's to enforce under their terms, not ours. Future eligibility is ours, so the consequences now run forward.
Not addressed here: the consequences still only bite downstream teams, not researchers who do not want a pre-disclosure seat.