Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Commit 731f40d

Browse files
committed
all updates for disclosure to private programs
1 parent cb8664c commit 731f40d

12 files changed

+125
-88
lines changed

docs/hackers/disclosure.md

Lines changed: 55 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,55 @@
1+
---
2+
title: "Disclosure"
3+
path: "/hackers/disclosure.html"
4+
id: "hackers/disclosure"
5+
---
6+
7+
Disclosure enables programs to be transparent about the security vulnerabilities found for their program. HackerOne's disclosure process balances transparency with control over what information is shared.
8+
9+
Programs can choose from 3 disclosure settings:
10+
11+
Option | Detail
12+
------ | -------
13+
Disclosure by Default | You or the security team can request disclosure for any closed report in the program. If the admin of the program agrees to disclosure, the contents of the report will be made public within 30 days.<br> <br>*This is the default setting for all verified programs*.
14+
Disclosure requiring Mutual Agreement | You can request disclosure for any closed report in the program. If the program security team agrees to disclosure, the contents of the report will be made public. If the security team doesn't take any action, the contents of the report will remain private. <br>*The program must request to opt-in to this option.*
15+
Disclosure Disabled | Disclosure isn't allowed for any report.
16+
17+
### Requesting Disclosure
18+
Both you and program members can request for disclosure. To request for disclosure:
19+
1. Go to the report you want to disclose.
20+
2. Make sure the report is closed.
21+
3. Select **Request disclosure** in the action picker at the bottom of the report.
22+
23+
![Request disclosure](./images/disclosure-1.png)
24+
25+
4. Select whether you want to disclose the **Full** report or a **Limited** version.
26+
27+
Option | Details
28+
------ | -------
29+
Full | Upon disclosure, the full contents of the report are visible including the:<ul><li>Vulnerability information</li><li>Summary</li><li>Timeline (this includes comments and attachments)</li></ul>*Note: Internal comments are hidden.*
30+
Limited | Only the summary and timeline of the activity are visible. All comments and attachments are hidden. Limited disclosure allows for greater control over sensitive or extraneous information.
31+
32+
5. *(Optional)* Enter a comment to describe your reasons for disclosure.
33+
6. Click **Post**.
34+
35+
After public disclosure has been requested, the admin of the of the program can choose to publicly disclose the report. They can select **Disclose** to disclose the report and also change the disclosure options to Full or Limited.
36+
37+
![disclose report](./images/disclosure-2.png)
38+
39+
When publishing reports, the security team can choose to disclose the report in full or limit the information published. The default is to display all the communication between the hacker and the security team from first report to resolution.
40+
41+
### Disclosure for Private Programs (beta)
42+
Private programs can also enable you to disclose a report to other hackers within the program. Upon disclosure, contents of the report will only be visible to participants in your private program. This enables you and other hackers to share your vulnerability findings with other hackers in the program, so that other hacker can be aware of what vulnerabilities have been found for a program.
43+
44+
You can request for disclosure in your private program following the same steps in the Requesting Disclosure section above.
45+
46+
When choosing to disclose the Full or Limited report, the options will only be specific to disclosing within your private program:
47+
48+
Option | Details
49+
------ | -------
50+
Full | Upon disclosure, the contents of the report will be visible to participants in your private program.
51+
Limited | Only the summary and timeline of activity will be visible to participants in your private program.
52+
53+
> Disclosure for private programs is currently in the beta phase. You'll be able to disclose reports for private programs if the program has opted-in to this feature.
54+
55+
For more information, please read the full [HackerOne Disclosure Guidelines](https://hackerone.com/disclosure-guidelines). If disclosure was accidentally initiated or you have concerns about this process, please [submit a support request](https://support.hackerone.com/hc/en-us/requests/new).

docs/hackers/images/disclosure-1.png

70 KB
Loading

docs/hackers/images/disclosure-2.png

29.7 KB
Loading

docs/hackers/public-disclosure.md

Lines changed: 0 additions & 40 deletions
This file was deleted.

docs/programs/disclosure.md

Lines changed: 66 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,66 @@
1+
---
2+
title: "Disclosure"
3+
path: "/programs/disclosure.html"
4+
id: "programs/disclosure"
5+
---
6+
7+
Disclosure enables you to be transparent about the security vulnerabilities found for your program. HackerOne's disclosure process balances transparency with control over what information is shared with the public.
8+
9+
Programs can choose from 3 disclosure settings:
10+
11+
Option | Details
12+
------ | -------
13+
Disclosure by Default | The hacker or your security team can request disclosure for any closed report in your program. If the admin of your program agrees to disclosure, the contents of the report will be made public within 30 days.<br> <br>*This is the default setting for all verified programs*.
14+
Disclosure requiring Mutual Agreement | The hacker can request disclosure for any closed report in your program. If your program security team agrees to disclosure, the contents of the report will be made public. If the security team doesn't take any action, the contents of the report will remain private. <br>*You must request to opt-in to this option.*
15+
Disclosure Disabled | Disclosure isn't allowed for any report.
16+
17+
### Requesting Disclosure
18+
Both hackers and program members can request for disclosure. To request for disclosure:
19+
1. Go to the report you want to disclose.
20+
2. Make sure the report is closed.
21+
3. Select **Request disclosure** in the action picker at the bottom of the report.
22+
23+
![Request Disclosure](./images/disclosure-1.png)
24+
25+
4. Select whether you want to disclose the **Full** report or a **Limited** version.
26+
27+
Option | Details
28+
------ | -------
29+
Full | Upon disclosure, the full contents of the report are visible including the:<li>Vulnerability information</li><li>Summary</li><li>Timeline (this includes comments and attachments)</li><br>*Note: Internal comments are kept hidden.*
30+
Limited | Only the summary and timeline of the activity are visible. All comments and attachments are hidden. Limited disclosure allows for greater control over sensitive or extraneous information.
31+
32+
5. *(Optional)* Enter a comment to describe your reasons for disclosure.
33+
34+
6. Click **Post**.
35+
36+
After disclosure has been requested, the admin of the of the program can choose to publicly disclose the report. They can select **Disclose** to disclose the report, and they can also change the disclosure options to Full or Limited.
37+
38+
![Disclose](./images/disclosure-2.png)
39+
40+
>Made a mistake? To remove a pending disclosure request, reopen and re-close the report.
41+
42+
### Disclosure for Private Programs (beta)
43+
If you’re running a private program, you can enable hackers to disclose a report within your private program. Upon disclosure, contents of the report will only be visible to participants in your private program. This enables hackers to share their vulnerability findings with other hackers in the program, and can also increase awareness for other hackers as they can better see what vulnerabilities have already been found for your program.
44+
45+
>Disclosure for private programs is currently in the beta phase. To opt-in to the feature contact your program manager.
46+
47+
To enable disclosure for private programs:
48+
1. Go to **Settings > Customization > Disclosure**.
49+
2. Select Yes to enable hackers to disclose reports in your private program.
50+
51+
Hackers and other members in your program can request for disclosure following the same steps above in the Requesting Disclosure section above.
52+
53+
When choosing to disclose the Full or Limited report, the options will only be specific to disclosing within your private program:
54+
55+
Option | Details
56+
------ | -------
57+
Full | Upon disclosure, the full contents of the report will be visible to participants in your private program.
58+
Limited | Only the summary and timeline of activity will be visible to participants in your private program.
59+
60+
![disclose for private program](./images/disclosure-3.png)
61+
62+
This diagram illustrates HackerOne's disclosure process:
63+
64+
![disclosure flowchart](./images/disclosure-4.png)
65+
66+
For more information, please read the full [HackerOne Disclosure Guidelines](https://hackerone.com/disclosure-guidelines). If disclosure was accidentally initiated or you have concerns about this process, please [submit a support request](https://support.hackerone.com/hc/en-us/requests/new).

docs/programs/images/disclosure-1.png

70 KB
Loading

docs/programs/images/disclosure-2.png

29.7 KB
Loading

docs/programs/images/disclosure-3.png

31.9 KB
Loading

docs/programs/images/disclosure-4.png

125 KB
Loading

docs/programs/public-disclosure.md

Lines changed: 0 additions & 44 deletions
This file was deleted.

src/pages/hackers/hackers-nav.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -98,7 +98,7 @@
9898
path: /hackers/weakness.html
9999
- title: Severity
100100
path: /hackers/severity.html
101-
- title: Public Disclosure
102-
path: /hackers/public-disclosure.html
101+
- title: Disclosure
102+
path: /hackers/disclosure.html
103103
- title: Keyboard Shortcuts
104104
path: /hackers/keyboard-shortcuts.html

src/pages/programs/programs-nav.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -120,8 +120,8 @@
120120
path: /programs/response-labels.html
121121
- title: Keyboard Shortcuts
122122
path: /programs/keyboard-shortcuts.html
123-
- title: Public Disclosure
124-
path: /programs/public-disclosure.html
123+
- title: Disclosure
124+
path: /programs/disclosure.html
125125
items:
126126
- title: Limiting Disclosed Information
127127
path: /programs/limiting-disclosed-information.html

0 commit comments

Comments
 (0)