Re: [tor-dev] Responsible disclosure

2014-09-18 Thread SiNA Rabbani
Just in case you need Nick's contact info: pub 3072R/0x21194EBB165733EA 2004-07-03 Key fingerprint = B35B F85B F194 89D0 4E28 C33C 2119 4EBB 1657 33EA uid [ unknown] Nick Mathewson uid [ unknown] Nick Mathewson uid [ unknown] Nick Mathews

Re: [tor-dev] Responsible disclosure

2014-09-18 Thread Damian Johnson
Hi Bram. If it's security related then we have... https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-security ... which is a closed list soly subsribed to by Nick and a few others. That said though we set that list up years ago for this purpose and I'm not spotting it advertised anywhere,

[tor-dev] Responsible disclosure

2014-09-18 Thread Bram de Boer
Hi, How can I responsibly report a bug that might affect security (e.g. possibility to DoS Tor nodes)? I searched the torproject.org website, but couldn't find any pointers with respect to responsible disclosure. Do I just file a trac ticket and/or drop it in this mailinglist? Do I report it d