Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

Latest commit

 

History

History
History
13 lines (9 loc) · 664 Bytes

File metadata and controls

13 lines (9 loc) · 664 Bytes
Copy raw file
Download raw file
Outline
Edit and raw actions

Security Policy

Reporting a Vulnerability

Please report a vulnerability to security@tinode.co.

Do NOT to report:

  • Firebase initialization tokens. The Firebase tokens are really public: they must be distributed with the client applications and consequently are not private by design.
  • Exposed /pprof and/or /expvar. We know they are exposed. It's intentional and harmless.
  • Exposed Prometheus metrics /metrics. Like above, it's intentional and harmless.
  • DMARC policy is not enabled p=none. We know and that's the way we like it for now.
  • Weak cipher suites (TLS 1.0) at *.tinode.co. Yes, we know. Does not look serious/important.
Morty Proxy This is a proxified and sanitized view of the page, visit original site.