Security

Found something? Tell us, and we'll tell you what we changed.

Email [email protected]. This covers redthreadsec.com, app.redthreadsec.com, trust.redthreadsec.com, the badge and verify service, the registry scanner and the atpp verifier. Machine-readable contact: /.well-known/security.txt.

What we promise

A human reply, a fix or an explanation, and credit if you want it.

  • We acknowledge every report within 3 business days and say whether we can reproduce it.
  • We tell you what we are changing and when, and we will not quietly fix it and move on.
  • We credit you publicly in the change notes unless you ask us not to.
  • We will not take legal action against good-faith research that stays inside the rules below.
Ground rules

Test against your own accounts, not other people's data.

  • Use a workspace you created. Don't access, change or delete data that isn't yours.
  • No denial-of-service, load testing, spam or social engineering of staff or customers.
  • Give us a reasonable chance to fix an issue before you publish it; 90 days is our default, and we will move faster for anything serious.
Badges

A badge image is a pointer, not proof. Here is how to check one without trusting us.

Any README badge is an image fetched from somebody's server, and the picture can show whatever that server decides. A researcher demonstrated this publicly with a proof of concept, and the point is right. So an ATPP claim does not live in the image. It lives in an in-toto statement signed with Ed25519 on our scan host, bound to the hash of the exact registry manifest that was scanned. Our web servers only hold the public key, so they cannot mint a claim that verifies.

The default badge is pinned: two files a publisher commits to their own repo (.atpp/badge.svg and .atpp/attestation.dsse.json), so nothing is fetched from us when their README renders. To check any claim:

pip install cryptography
curl -sO https://raw.githubusercontent.com/bl014h/atpp/main/atpp.py
python3 atpp.py verify <namespace>/<server>     # or a path to a repo with an .atpp/ folder

Pinned keys: /.well-known/atpp-keys.json (this file can only revoke a key; the verifier ships the keys it trusts). Genuine verify pages are only served from trust.redthreadsec.com.