Status

CURRENT

Published

 

Updated

 

Introduction

Thank you for helping keep Telecom Wiki and its community safe.

Telecom Wiki is a non-commercial hobby site run by volunteers for the telecommunications community. We take the security of the site and our visitors seriously, and we genuinely appreciate the time and effort of anyone who reports a potential issue responsibly.

Reporting a Security Issue

If you believe you have found a security vulnerability, please email us at:

[email protected]

To help us understand and address the issue quickly, please include where you can:

  • A description of the vulnerability and its potential impact
  • The steps needed to reproduce it
  • The affected page, URL, or component
  • Any relevant logs, screenshots, or proof-of-concept details

If you are emailing us we recommend encrypting your email with our PGP key if possible. You may find our PGP key at https://telecom.wiki/.well-known/pgp-key.txt.

What to Expect

We will respond as soon as we reasonably can. Please bear in mind that Telecom Wiki is maintained by volunteers in their spare time, so response and resolution times may vary. We will do our best to:

  • Acknowledge your report when we are able to
  • Investigate and validate the issue
  • Keep you informed of our progress where appropriate
  • Address confirmed issues as our time and resources allow

No Bug Bounty Program

Please note that Telecom Wiki is a community hobby project. We do not operate a bug bounty program and we do not have the budget to offer monetary rewards for security reports. Reports are received and handled on a voluntary, good-faith basis.

We are, of course, very grateful for any reports, and we are happy to acknowledge contributors who responsibly disclose valid issues, if they would like to be credited.

Responsible Disclosure

To protect our community while an issue is being investigated and fixed, we ask that you:

  • Give us a reasonable opportunity to address the issue before disclosing it publicly
  • Avoid accessing, modifying, or deleting data that does not belong to you
  • Avoid actions that could degrade, disrupt, or damage the site or its services for other users
  • Act in good faith and within the bounds of applicable law

Out of Scope

The following are generally not considered security vulnerabilities for the purposes of this policy:

  • Reports from automated scanners without a demonstrated, exploitable impact
  • Missing security headers or best-practice recommendations with no real-world impact
  • Denial-of-service (DoS) attacks or volumetric testing
  • Social engineering of our volunteers or community members
  • Issues in third-party services we use but do not control

Thank You

This wiki exists thanks to the community, and so does its security. We appreciate you taking the time to report issues responsibly and help keep Telecom Wiki safe for everyone.