Reporting a vulnerability
Write to luka@lukaloehr.com with the subject "Security report". Include what you found, how to reproduce it, and what an attacker could do with it. English or German. Please do not put details in public issues or social media before we have fixed it.
Machine-readable: /.well-known/security.txt.
What we promise
- An answer within 3 working days and an assessment within 10 working days.
- Fixes in line with severity: critical within 72 hours, high within 7 days, medium within 30 days.
- We tell you when it is fixed, and credit you if you want.
- We will not take legal action against research done in good faith under the rules below.
There is no paid bug bounty.
Scope
- kiste.run, desktop.kiste.run and the API under kiste.run/v1
- The infrastructure of kiste.stream (not the services customers publish there)
- The
kisteCLI and its installer - Isolation between machines, and between a machine and the host or control plane
Rules for research
- Use only your own account and your own machines. Ask us for a second test account if you need one to test isolation.
- Do not access, change or delete other people's data. If you reach any by accident, stop, do not keep it, and tell us.
- No denial of service, load tests, spam, social engineering or physical attacks.
- Do not use a machine to attack third parties.
- Give us reasonable time to fix before you publish; we aim for 90 days at most.
Security measures
Every machine is a Firecracker microVM with its own kernel. The compute server exposes no port to the Internet. Passwords and tokens are stored only as hashes. Backups are encrypted with keys only Kiste holds. The full list is Annex 2 of the Data Processing Agreement. Kiste holds no security certification; we are preparing for ISO/IEC 27001.
Schwachstellen melden
Schreiben Sie an luka@lukaloehr.com mit dem Betreff „Security report“: was Sie gefunden haben, wie man es nachvollzieht und was ein Angreifer damit tun könnte. Bitte veröffentlichen Sie Details erst, wenn wir die Lücke behoben haben.
Wir antworten innerhalb von 3 Werktagen und bewerten den Fund innerhalb von 10 Werktagen. Kritische Lücken beheben wir innerhalb von 72 Stunden, hohe innerhalb von 7 Tagen, mittlere innerhalb von 30 Tagen. Gegen Forschung in gutem Glauben nach den obigen Regeln gehen wir nicht rechtlich vor. Testen Sie nur mit Ihrem eigenen Konto und Ihren eigenen Maschinen, greifen Sie nicht auf fremde Daten zu, keine Überlastungs-, Spam- oder Social-Engineering-Tests. Eine bezahlte Bug-Bounty gibt es nicht.