Reporting a vulnerability
If you’ve found a way into someone’s files, keys or devices through Qurb, thank you — and please tell us before anyone else.
How
Please don’t describe it in a public issue. The repository doesn’t accept private reports through GitHub yet. Until it does, open an issue that says only that you have a security problem to report, with no details, and a private way to send them will be arranged with you there.
No bounty, and no promised response time yet. Qurb is pre-release and has no company behind it. What it can promise is that a report is taken seriously, fixed in the open, and credited if you want it to be.
What helps
- What you did, on which devices and which version — every build says its own:
qurb version, or Settings → Version. - What you could reach that you shouldn’t have: files, filenames, keys, a device you weren’t paired with.
- Whether it needs the other person’s device, their network, or neither.
What Qurb already says about itself
Some limits are known and written down rather than hidden — your devices share one key, and removing a device doesn’t take that key away. They’re on the security page; a report about one of them is still welcome if it goes further than the page says.