DC416 Vulnerability Disclosure Policy

How DC416 handles vulnerability reports, coordinates disclosure with vendors, and assigns CVE identifiers.

DC416 is Toronto's DEFCON group. This policy covers how we accept, coordinate, and publish vulnerability reports, including the reservation and assignment of CVE identifiers where applicable.

Scope

DC416 will accept vulnerability reports for two categories:

If the affected vendor is itself a CNA, DC416 will defer to that vendor's scope. If the vendor is not a CNA, DC416 may coordinate disclosure and reserve a CVE identifier under our scope.

How to report

Vulnerabilities in DC416's own assets

Email a detailed report to cve@defcontoronto.ca. Include enough information for us to triage and reproduce the issue: affected asset, steps to reproduce, expected versus actual behavior, and any proof-of-concept material.

Vulnerabilities in third-party assets

Third-party vulnerability reports will only be considered for CVE coordination when presented at a scheduled DC416 monthly meetup. We do not accept third-party reports through email, form, or private channel.

Why the meeting-presentation gate. DC416 is a volunteer-run community. Tying third-party coordination to our monthly meetup keeps the workload finite and grounded in the community that vouches for the research. This mirrors AHA!'s long-running practice.

If you plan to present research at a DC416 meetup that you would like DC416 to coordinate as a CVE, let us know in advance by emailing cve@defcontoronto.ca. Details on meetup timing are at defcontoronto.ca/calendar.

What we ask of researchers

What we commit to

Safe harbor

DC416 will not pursue civil action, initiate a criminal complaint, or report to law enforcement any researcher for good-faith violations of this policy. We consider security research and vulnerability disclosure conducted consistent with this policy to be authorized, lawful, and helpful to the overall security of the Internet.

This safe harbor extends only to the components of the research conducted in good faith and in accordance with this policy. Actions inconsistent with this policy, including but not limited to extortion, unauthorized data access beyond proof of concept, or damage to systems, are not covered.

Note: this safe harbor is DC416's commitment. Third-party vendors and platforms have their own terms of service. DC416 cannot grant safe harbor for research against systems we do not operate.

Sponsor and partner disclosure

DC416 receives sponsorship from Stan and may have similar arrangements with other companies. The current list of sponsors and partners is published at defcontoronto.ca.

Where a coordinated vulnerability disclosure involves a product owned, developed, or operated by a DC416 sponsor or partner, the assignment and coordination are handled by a DC416 organizer with no financial, employment, or advisory relationship to that sponsor. The sponsorship relationship is disclosed in the public CVE record notes.

CVE identifier assignment

DC416 is preparing to become a CVE Numbering Authority. Until the CNA application is activated, DC416 will route CVE identifier requests to the appropriate CNA of Last Resort: Red Hat CNA-LR for open-source projects, or MITRE CNA-LR for other products.

Once activated, DC416 will assign CVE identifiers directly for vulnerabilities within our approved scope, in accordance with the CVE Program's Operational Rules.

Publication

Advisories are published at defcontoronto.ca/advisories/ after the embargo period ends. Each advisory includes the affected product, version range, technical description, proof-of-concept where safe, remediation guidance, and credit to the researcher.

Contact

Email: cve@defcontoronto.ca

Discord: discord.gg/VDy69zgfc3

Website: defcontoronto.ca

Attribution & license. This policy is adapted from the Austin Hackers Anonymous (AHA!) Vulnerability Disclosure Policy, itself based on the disclose.io Policymaker. Both are licensed under CC BY-SA 4.0, and this document is published under the same license. Adapt it for your own community; credit DC416 and AHA! as source.