Security
Report a vulnerability
Section titled “Report a vulnerability”security@lake8.dev — encrypted reports preferred.
PGP key and fingerprint: /security/pgp/
Response times: acknowledgment within 7 days, assessment within 21 days, fix or accepted risk within 90 days for High/Critical findings.
Security programme
Section titled “Security programme”- Vulnerability Disclosure Policy — scope, safe harbour, coordinated disclosure
- Product Security Incident Response — severity classification, response process, known accepted risks
Public finding register
Section titled “Public finding register”All findings — open and closed — are published at /security/red-team-2026-08/
Known open findings
Section titled “Known open findings”| ID | Severity | Description | Fix |
|---|---|---|---|
| F-001-REV | High | Session binding not implemented | Q2 2027 |
| F-ISO | Medium | Block-cipher accumulator not bound to a handle — fail-closed | Q2 2027 |
| F-003/B1 | Low | PIN in cleartext over USB HID | Q2 2027 |
Terms of ServicePrivacy PolicySecurity contact: security@lake8.devVulnerability Disclosure Policy
Alcuni contenuti sono stati redatti con il supporto di strumenti di intelligenza artificiale generativa e revisionati dall'autore. Le immagini hardware hanno scopo puramente illustrativo.
Some content was drafted with the support of generative AI tools and reviewed by the author. Hardware images are purely illustrative.
Einige Inhalte wurden mit Unterstützung generativer KI-Werkzeuge verfasst und vom Autor überprüft. Hardware-Abbildungen dienen ausschließlich illustrativen Zwecken.
Algunos contenidos han sido redactados con el apoyo de herramientas de IA generativa y revisados por el autor. Las imágenes de hardware tienen carácter meramente ilustrativo.
In caso di conflitto tra versioni linguistiche, prevale il testo in lingua italiana.