Disclosure
Reverse-engineering work regularly turns up defects in software we do not own. This page is what happens next. It is a policy rather than a preference: it does not change because a vendor is slow, unresponsive, or unhappy with what we found.
Day 0. The vendor receives the finding in full: affected component and versions, reproduction steps, what an attacker gains, and our assessment of severity. Nothing is held back from the people who have to fix it.
Day 7. We ask for confirmation of receipt. If none arrives we try a second channel — a security address, a maintainer, a national CERT. Silence does not stop the clock; it only means we publish without having been able to check the fix.
Day 90. The advisory goes public, whether or not a fix shipped. We extend that deadline for a vendor who is engaged and making progress, and we say so in the advisory when we do. An extension is granted for progress, never for silence.
Two things shorten it. If we find an issue already being exploited, the people at risk outrank the vendor's release schedule and we publish the mitigation immediately. If a fix is generally available sooner, so is the advisory — there is no reason to sit on it.
Enough for an operator to decide whether they are exposed and what to do about it: affected component, affected versions, the class of defect, realistic impact, the fixed version, and the timeline of the disclosure itself — including the parts that reflect badly on us.
Not included: working exploit code. A proof-of-concept that a reader can point at production is a weapon, and shipping one does not make the advisory more true. Where a demonstration is genuinely needed to establish severity, it goes to the vendor and stops there.
Defects in our own software, or in a deployment we built, go to hello@lyphere.com. Include the version and how to reproduce it. You will get a human, not a ticket number.
We will not pursue legal action against anyone who reports a defect to us in good faith, keeps it confidential until it is fixed, and does not access, alter or destroy data belonging to anyone else while finding it. That protection is ours to give and we give it plainly.
None published yet. Findings currently under embargo are not listed here, deliberately — naming an unannounced target is itself a disclosure, and the vendor is entitled to hear it before the internet does. Published advisories will appear here with their full timeline, including the dates we missed.