DC416 Vulnerability Disclosure Policy
How DC416 handles vulnerability reports, coordinates disclosure with vendors, and assigns CVE identifiers.
DC416 is Toronto's DEFCON group. This policy covers how we accept, coordinate, and publish vulnerability reports, including the reservation and assignment of CVE identifiers where applicable.
Scope
DC416 will accept vulnerability reports for two categories:
- DC416's own digital assets. Vulnerabilities in the DC416 website
(
defcontoronto.ca), the DC416 events platform (events.defcontoronto.ca), and any other infrastructure operated by DC416. - Third-party assets, subject to conditions. Vulnerabilities discovered by researchers in collaboration with DC416, where the affected product or service is not already within the scope of another CVE Numbering Authority.
If the affected vendor is itself a CNA, DC416 will defer to that vendor's scope. If the vendor is not a CNA, DC416 may coordinate disclosure and reserve a CVE identifier under our scope.
How to report
Vulnerabilities in DC416's own assets
Email a detailed report to cve@defcontoronto.ca. Include enough information for us to triage and reproduce the issue: affected asset, steps to reproduce, expected versus actual behavior, and any proof-of-concept material.
Vulnerabilities in third-party assets
Third-party vulnerability reports will only be considered for CVE coordination when presented at a scheduled DC416 monthly meetup. We do not accept third-party reports through email, form, or private channel.
Why the meeting-presentation gate. DC416 is a volunteer-run community. Tying third-party coordination to our monthly meetup keeps the workload finite and grounded in the community that vouches for the research. This mirrors AHA!'s long-running practice.
If you plan to present research at a DC416 meetup that you would like DC416 to coordinate as a CVE, let us know in advance by emailing cve@defcontoronto.ca. Details on meetup timing are at defcontoronto.ca/calendar.
What we ask of researchers
- Report any vulnerability you have discovered promptly.
- Give us at least 60 days from your initial report before disclosing the issue publicly. Where the affected vendor has a longer stated policy, we may negotiate an embargo of up to 90 days.
- Limit the amount of data you access to the minimum required to demonstrate a proof of concept.
- Do not degrade, damage, or destroy any system or data.
- Do not access or modify data that is not your own beyond what is needed for the proof of concept.
- Do not engage in extortion. Requesting compensation in exchange for withholding disclosure is grounds for immediate loss of safe harbor and coordination.
What we commit to
- Respond to your report promptly.
- Work with you to understand and validate the report.
- Coordinate with the affected vendor in good faith.
- Credit you as the discoverer on the published record, or maintain your anonymity if you request it.
- Publish an advisory at defcontoronto.ca/advisories/ once coordinated disclosure is complete.
- Not pursue legal action against you for good-faith research conducted under this policy.
Safe harbor
DC416 will not pursue civil action, initiate a criminal complaint, or report to law enforcement any researcher for good-faith violations of this policy. We consider security research and vulnerability disclosure conducted consistent with this policy to be authorized, lawful, and helpful to the overall security of the Internet.
This safe harbor extends only to the components of the research conducted in good faith and in accordance with this policy. Actions inconsistent with this policy, including but not limited to extortion, unauthorized data access beyond proof of concept, or damage to systems, are not covered.
Note: this safe harbor is DC416's commitment. Third-party vendors and platforms have their own terms of service. DC416 cannot grant safe harbor for research against systems we do not operate.
Sponsor and partner disclosure
DC416 receives sponsorship from Stan and may have similar arrangements with other companies. The current list of sponsors and partners is published at defcontoronto.ca.
Where a coordinated vulnerability disclosure involves a product owned, developed, or operated by a DC416 sponsor or partner, the assignment and coordination are handled by a DC416 organizer with no financial, employment, or advisory relationship to that sponsor. The sponsorship relationship is disclosed in the public CVE record notes.
CVE identifier assignment
DC416 is preparing to become a CVE Numbering Authority. Until the CNA application is activated, DC416 will route CVE identifier requests to the appropriate CNA of Last Resort: Red Hat CNA-LR for open-source projects, or MITRE CNA-LR for other products.
Once activated, DC416 will assign CVE identifiers directly for vulnerabilities within our approved scope, in accordance with the CVE Program's Operational Rules.
Publication
Advisories are published at defcontoronto.ca/advisories/ after the embargo period ends. Each advisory includes the affected product, version range, technical description, proof-of-concept where safe, remediation guidance, and credit to the researcher.
Contact
Email: cve@defcontoronto.ca
Discord: discord.gg/VDy69zgfc3
Website: defcontoronto.ca
Attribution & license. This policy is adapted from the Austin Hackers Anonymous (AHA!) Vulnerability Disclosure Policy, itself based on the disclose.io Policymaker. Both are licensed under CC BY-SA 4.0, and this document is published under the same license. Adapt it for your own community; credit DC416 and AHA! as source.