Introduction
Thank you for helping keep Telecom Wiki and its community safe.
Telecom Wiki is a non-commercial hobby site run by volunteers for the telecommunications community. We take the security of the site and our visitors seriously, and we genuinely appreciate the time and effort of anyone who reports a potential issue responsibly.
Reporting a Security Issue
If you believe you have found a security vulnerability, please email us at:
To help us understand and address the issue quickly, please include where you can:
- A description of the vulnerability and its potential impact
- The steps needed to reproduce it
- The affected page, URL, or component
- Any relevant logs, screenshots, or proof-of-concept details
If you are emailing us we recommend encrypting your email with our PGP key if possible. You may find our PGP key at https://telecom.wiki/.well-known/pgp-key.txt.
What to Expect
We will respond as soon as we reasonably can. Please bear in mind that Telecom Wiki is maintained by volunteers in their spare time, so response and resolution times may vary. We will do our best to:
- Acknowledge your report when we are able to
- Investigate and validate the issue
- Keep you informed of our progress where appropriate
- Address confirmed issues as our time and resources allow
No Bug Bounty Program
Please note that Telecom Wiki is a community hobby project. We do not operate a bug bounty program and we do not have the budget to offer monetary rewards for security reports. Reports are received and handled on a voluntary, good-faith basis.
We are, of course, very grateful for any reports, and we are happy to acknowledge contributors who responsibly disclose valid issues, if they would like to be credited.
Responsible Disclosure
To protect our community while an issue is being investigated and fixed, we ask that you:
- Give us a reasonable opportunity to address the issue before disclosing it publicly
- Avoid accessing, modifying, or deleting data that does not belong to you
- Avoid actions that could degrade, disrupt, or damage the site or its services for other users
- Act in good faith and within the bounds of applicable law
Out of Scope
The following are generally not considered security vulnerabilities for the purposes of this policy:
- Reports from automated scanners without a demonstrated, exploitable impact
- Missing security headers or best-practice recommendations with no real-world impact
- Denial-of-service (DoS) attacks or volumetric testing
- Social engineering of our volunteers or community members
- Issues in third-party services we use but do not control
Thank You
This wiki exists thanks to the community, and so does its security. We appreciate you taking the time to report issues responsibly and help keep Telecom Wiki safe for everyone.