Definition
我如何向 CirculeID 报告安全漏洞?
Email ceo@fistasolutions.com with "Security disclosure" as the subject and enough detail to reproduce the issue. We acknowledge within one business day and give an initial assessment within five, with a named contact who stays with the report until it is closed.
Please do not post it publicly first, and please do not test against other customers’ data. Beyond that we are not going to threaten researchers with legal language: a report made in good faith is a favour, and we will treat it as one.
披露
您报告之后会发生什么
- 01
已确认收到
一个工作日内由真人而非自动回复答复您,并附上接手此事者的姓名。
- 02
已评估
五个工作日内,我们会告知能否复现、如何评估影响,以及打算怎么做。
- 03
已解析
时间取决于严重程度。您得到的是进展而不是沉默,修复上线时我们会告知您。
- 04
已结束
我们会确认处理结果,若您愿意署名则予以致谢,并与您商定任何协同披露的时间安排。
访问
谁可以接触客户数据
| Party | What they can reach | 控制 |
|---|---|---|
| Anyone with a data carrier | The public tier of a passport | The product group’s access policy |
| Verified third parties | Treatment, repair or regulatory tiers | A revocable credential from a trusted issuer |
| Customer systems | Everything in that tenant | Scoped keys, per environment and capability |
| CirculeID engineering | Production data, for an approved reason | Restricted, reason-required, logged in the customer-visible audit trail |
| Subprocessors | Only what their function requires | Named in the data processing terms; changes notified in advance |
实践做法
已经具备什么
加密
传输中与静态存储时均加密,且密钥与数据分开管理。
密钥托管
签名密钥存放于硬件安全模块,或完全由客户保留。
审计日志
包括我们自己的运维访问,都会记入客户可以查阅的审计轨迹。
最小权限
按角色和事由授予访问权限,并定期复核而非任其累积。
直接的违规通知
受影响的客户会尽早收到直接通知,其中也包含仍未确定的事项。
对研究者友好
善意的报告被视为一种帮助,而不是一桩法律事务。
答疑
常见问题
我如何报告漏洞?
Email ceo@fistasolutions.com with "Security disclosure" as the subject. Include enough detail to reproduce the issue. Please do not open a public issue, post it publicly, or test against other customers' data before we have had a chance to respond.
作为回应,你们承诺什么?
一个工作日内确认收到,五个工作日内给出初步评估,并指定专人跟进直至报告结案。即便结论是该行为属于预期设计,我们也会告知调查结果;若您愿意具名,我们会予以致谢。
CirculeID 的员工能读取客户的护照数据吗?
生产环境访问受到限制,需经批准的事由,并记入客户可以查阅的同一份审计轨迹。我们不宣称零知识:平台托管这份记录并按请求解析,因此必然会处理数据。任何一边提供公开护照、一边作出相反宣称的供应商,描述的都是架构做不到的事。
如果发生数据泄露会怎样?
受影响的客户会收到直接通知,而不仅是一个状态页面,内容包括我们已知的、尚未确定的,以及正在采取的措施。GDPR 及适用行业规则下的通知义务,均在法定时限内履行。我们宁可发出一份不完整的早期通知,也不愿发出一份体面的迟到通知。
你们设有漏洞赏金计划吗?
这不是一个公布了赏金等级的正式项目。我们会确认每一份报告,并在报告确有实际影响时逐案给予研究者奖励。宣布一个我们无法稳定运营的赏金计划,还不如坦率说明目前的做法。