Reporting a security problem
How to tell us about a vulnerability in Koven, what we will do about it, and our promise not to come after you for looking.
Last updated
The short version
Email support@kovengames.com with "security" in the subject line. Tell us what you found and how to reproduce it. You will hear back from a person within three working days.
Please do not post it publicly until we have had a chance to fix it. We aim to have a fix out within ninety days, and we will keep you posted while we work.
We will not take legal action against you for research done in good faith under this policy, and we will not ask your internet provider or your employer to either.
There is no bounty programme. We have no money for one yet and we would rather say so than imply otherwise. We will credit you by name if you would like us to.
This summary is here so that the rest is easier to follow. The sections below are the part that counts.
1How to report something
In plain EnglishEmail us, tell us what you found, and tell us how to see it for ourselves.
Send it to support@kovengames.com with "security" at the start of the subject line. That routes it away from the ordinary support queue and to somebody who can act on it.
A report we can reproduce gets fixed in days. A report we cannot gets a reply asking for more, which costs both of us a week. The more of the following you can give us, the faster this goes.
- What you found, in a sentence, before the detail.
- The exact steps to reproduce it, including the room code, deck or account you used.
- What an attacker gets out of it. A crash and a data leak need different answers from us.
- Anything you think we should not do, such as an account we should not delete because it is your proof.
- How you would like to be credited, or that you would rather not be.
If what you have found is being actively exploited, say so in the subject line. We will treat it as an incident rather than as a report.
2What happens next
In plain EnglishA person replies within three working days, we tell you what we think it is, and we keep you posted until it is fixed.
| When | What we do |
|---|---|
| Within 3 working days | A person replies. Not an autoresponder, and not a ticket number on its own. |
| Within 10 working days | We tell you whether we have reproduced it, how serious we think it is, and roughly when we expect a fix. |
| Every 14 days after that | An update, even when the update is that we are still working on it. Silence is the thing that makes people publish early. |
| Within 90 days | A fix is released, or we explain why it is taking longer and agree a new date with you. |
| After the fix | We credit you if you want it, and we are happy for you to write it up. |
If we disagree about how serious something is, we will say why rather than quietly downgrading it. You are welcome to disagree back.
3Our promise to you
In plain EnglishResearch in good faith under this policy is authorised. We will not sue you, and we will not report you.
We consider security research carried out in line with this policy to be authorised access. We will not bring a claim against you under the Computer Misuse Act 1990 or any equivalent law elsewhere, we will not report you to the police, and we will not contact your employer or your internet provider about it.
If a third party brings a claim against you for work you did under this policy, tell us and we will make it clear that your research was authorised.
This promise covers research done in good faith. It stops covering you at the point you take somebody else’s data, damage something, or use what you found for anything other than telling us about it.
4What is in scope
In plain EnglishThe apps, the website, the game servers and the database. If in doubt, ask.
| System | What it is |
|---|---|
| The Koven mobile apps | The iOS and Android apps, on any version we still support. |
| kovengames.com | The marketing site, the web player, the shared screen and the community library. |
| The game servers | The realtime room engine and the other server functions the apps talk to. |
| The database | Anything reachable with a key that ships in the apps, which is everything a player can query. |
We care most about anything that reaches a room somebody was not invited to, anything that shows a player content that has not been moderated, anything that reveals personal data about another player, and anything that lets somebody act as a moderator when they are not one.
5What is out of scope
In plain EnglishFindings from a scanner with no working attack behind them, and anything that needs us to attack our own players.
We will read everything, but the following will usually get a polite no rather than a fix. None of it is a rule about what you may look at. It is a description of what we already know.
- Output from an automated scanner with no demonstrated impact attached.
- Missing security headers, cookie flags or TLS configuration with no working attack behind them.
- Rate limits you got past by using a lot of different addresses. We know, and stopping that is a job for the network in front of us.
- The publishable key that ships in the apps. It is meant to be public, and row level security is what stands behind it.
- Anything that needs physical access to somebody’s unlocked phone.
- Reports that Koven does not implement a feature you would like it to.
6What we ask of you
In plain EnglishUse your own accounts, take only what you need to prove it, and give us a chance to fix it first.
- Test against your own accounts, your own rooms and your own decks. Children use this product, and a room you were not invited to has real people in it.
- Take the minimum you need to demonstrate the problem, then stop. If you reach personal data, stop straight away and tell us what you reached rather than how much of it you could have taken.
- Do not run denial of service tests, do not send bulk automated traffic, and do not spam the report or waitlist forms.
- Do not use social engineering against our staff, our suppliers or our players.
- Give us ninety days before publishing, and talk to us if you need to move that date.
If you break something by accident, tell us. We would far rather hear it from you than find it ourselves.
7How we build for this
In plain EnglishServer authoritative gameplay, row level security on every table, and content that is private until a person has reviewed it.
Some context, so a report can be aimed at the interesting parts. The client never decides scores, phases or timers: if a client could lie about it, the server owns it. Every table that holds anything belonging to a person has row level security on it, and the negative case is tested rather than assumed.
Everything anybody writes starts private and unapproved. Nothing a player has made is visible to a stranger until it has been through moderation, which is the promise the whole product rests on.
If you find a way around either of those two, that is the report we most want to receive.