5 ms·
Security Vulnerability Reporting Policy
- fintler 9y ago> Priority will be granted to encrypted reports – please include your PGP public key with such reports. Is this a common thing? Why should they give priority to encrypted reports?
- TrainedMonkey 9y agoTo encourage people to use encryption?
- staticautomatic 9y agoShouldn't they give priority to unencrypted ones since they're ostensibly more likely to be publicly exposed?
- jamestimmins 9y agoIt could be a somewhat arbitrary bar to separate the wheat from the chaff. If they get a lot of questionable submissions, prioritizing encrypted submissions means prioritizing submitters who at least know enough to use encryption.
- tptacek 9y agoAnd? Lots of companies do; it's a best practice.
- cpach 9y agoYep. Also lots of companies that should do it, but doesn’t.
- tptacek 9y agoThe title on this story changed long after I wrote this; the original title was something like, "Tesla accepts reports encrypted to a PGP key."
- LukeHoersten 9y agoI thought it was an interesting position for what is ostensibly a car company to take. If this is common for car companies, who are more and more becoming software companies, I was unaware. Also, personally I’m a big fan of yours.
- milkshakes 9y agoat least they posted the public key instead of the private one like adobe: https://arstechnica.com/information-technology/2017/09/in-spectacular-fail-adobe-security-team-posts-private-pgp-key-on-blog/ https://arstechnica.com/information-technology/2017/09/in-sp...
- coenhyde 9y agoAlso a bug bounty: https://bugcrowd.com/tesla https://bugcrowd.com/tesla