Reporting a security issue
If you have found a security issue in anything of ours, write to info@hemarostfritt.se. We read every report and answer every one that concerns something we control.
What this site is
It says something about where the time is worth spending. hemarostfritt.se is static pages. There is no login, no form, no database and no customer data held here. The pages are built from a repository and published as finished files.
The attack surface is small, then, but it is not nothing.
In scope
- hemarostfritt.se and its subdomains
- The DNS configuration for the domain, including the mail records
- Our email, meaning addresses ending in @hemarostfritt.se
Out of scope
We are glad to read reports about the following, but we can rarely act on them, and they belong with whoever actually controls the system.
- Our customers’ and suppliers’ systems, even where we are named in them
- Services run by third parties, such as our hosting provider or our analytics tool
- Physical security, access to the workshop and anything concerning staff
- Denial-of-service attacks and load testing. Do not run them against us.
- Social engineering of our people, including phishing as a test
- A missing recommended setting without a demonstrated consequence. A grade from a scanner is not a vulnerability.
How to report
Email info@hemarostfritt.se with "security" in the subject line and it will reach the right desk sooner. Swedish or English are both fine.
Include what lets us reproduce it: the address concerned, what you did, what happened and what you expected instead. A screenshot or a log extract helps. If you have a view on what the flaw could lead to, write that too.
What you can expect from us
- We acknowledge your report within five working days.
- We tell you whether we consider it an issue and why if we do not.
- We keep you informed while we work, and say so when it is fixed.
- We will credit you as the finder if you want that. Staying anonymous is equally fine.
What we ask of you
- Do not go looking. Do not scan, test or probe our systems.
- Do not reach into data that is not yours, and read no more than it takes to show the problem.
- Change nothing, delete nothing and do not disrupt the service.
- Give us reasonable time to fix it before going public. Ninety days is a common and reasonable window, and do get in touch if you need a different one.
- Report to us first, not to somebody else.
No payment, but our thanks
We do not pay for reports. We are a workshop that works in stainless steel, not a technology company with a budget for it, and we would rather say so plainly than let you put in work believing there is money at the end of it.
What we can offer is an answer from a person, a fix and our thanks. If you would like to be named, we are glad to.
What we cannot promise
This page is a channel for telling us about something you have come across. It is not an invitation to go looking, and we grant no permission to test our systems.
So we cannot promise that no legal action will follow. Such a promise would not be ours to give while we are asking you to refrain, and we cannot speak for third parties whose systems are involved, such as the company that hosts the site for us.
That said, we have no intention of making an issue of someone getting in touch in good faith about something they happened to see. We want to know, we want to fix it and we want to thank you. But we would rather write what we can stand behind than a promise that looks safer than it is.