Skip to content

Security: Hypfer/Valetudo

Security

SECURITY.md

SECURITY dot md (not the TLD)

Valetudo is insecure software built by an even more insecure person.
It should not under any circumstance be used by anyone at all.

If it is used regardless, the terms of the ./LICENSE apply.

Additionally, it is highly recommended to use network-level restrictions to jail Valetudo and never let it see the outside world. It actually likes that. It wants to live that way.

But what if I find a security vulnerability?

Well, first of all, you've probably meant to say "bug". But that term comes with less clout I guess.

As said in many places, the whole idea of this software is to run locally and offline; not really processing much user-controlled input. So.. with that context, impressive that you did discover something within Valetudo regardless. You did, right?

That said, blast radius is probably going to be not all that large, so the whole theater probably doesn't make all this much sense within the context of this project.

FWIW, Valetudo is the result of IT security research, so we're kinda on the same team.
That doesn't mean that there couldn't be any mistakes, of course.

For those, just talk like a normal person that wants to contribute to the betterment of the world (and not their personal brand). Then stuff should work out hassle-free.

Further reading: ./CODE_OF_CONDUCT.md

Why does this file exist?

Buddy, I am asking myself the same thing.

The historical context is some cold email by some startup wanting to sell me on some automated security scanning stuff. I'd like to not receive those emails, but I also like a good soapbox. So there we are.

I'd like to leave you with this:

Imagine a world where all software that doesn't need to be cloud connected also simply isn't.
Imagine a world in which we engineer our systems in ways that fail gracefully, instead of just gluing layers and layers of firefighting on top after the fact.

There aren't any published security advisories