Product Security Incident Response
What this document is
Section titled “What this document is”This document describes how lake8.dev receives, assesses, and responds to security vulnerabilities in Crypt-in products. It complements the Vulnerability Disclosure Policy.
Severity classification
Section titled “Severity classification”| Severity | Definition | Example |
|---|---|---|
| Critical | Remote code execution, key material exfiltration, authentication bypass without physical access | — |
| High | Session hijacking with physical access, PIN bypass, licence bypass | F-001-REV, F-003/B1 |
| Medium | Information disclosure, denial of service, weakening of cryptographic guarantees | — |
| Low | Minor information leakage, UX-level security issues | F-NEW-RAM (mitigated) |
Response process
Section titled “Response process”- Receipt — acknowledgment within 7 days
- Triage — severity assigned, finding ID issued (format:
F-NNN-TAG), reporter notified within 21 days - Fix or mitigation — Critical/High within 90 days; Medium/Low best effort with communicated timeline
- Disclosure — coordinated with reporter before any publication; all findings published in the public register
Known accepted risks
Section titled “Known accepted risks”| ID | Severity | Status | Fix milestone |
|---|---|---|---|
| F-001-REV | High | Open — accepted | Q2 2027 (session binding) |
| F-003/B1 | High | Open — accepted | Q2 2027 (challenge-response) |
Mitigations in place: auto-lock at ~10 minutes of inactivity (reset by any HID command); physical disconnection closes the session in <5 seconds.
What we will never do
Section titled “What we will never do”- Ask for indefinite silence on a finding
- Deny a finding that is reproducible on hardware
- Publish a fix without crediting the reporter (unless anonymity is requested)
- Claim a finding is fixed before it is verified on hardware
Contact
Section titled “Contact”security@lake8.dev — encrypted reports preferred
PGP key and fingerprint: /security/pgp/
Terms of ServicePrivacy PolicySecurity contact: security@lake8.devVulnerability Disclosure Policy
Alcuni contenuti sono stati redatti con il supporto di strumenti di intelligenza artificiale generativa e revisionati dall'autore. Le immagini hardware hanno scopo puramente illustrativo.
Some content was drafted with the support of generative AI tools and reviewed by the author. Hardware images are purely illustrative.
Einige Inhalte wurden mit Unterstützung generativer KI-Werkzeuge verfasst und vom Autor überprüft. Hardware-Abbildungen dienen ausschließlich illustrativen Zwecken.
Algunos contenidos han sido redactados con el apoyo de herramientas de IA generativa y revisados por el autor. Las imágenes de hardware tienen carácter meramente ilustrativo.
In caso di conflitto tra versioni linguistiche, prevale il testo in lingua italiana.