The Device Layer

Responsible disclosure

Security contact for this site, and the publication's policy on handling vulnerability information in its reporting.

Security contact

Found a security issue with this website? Report it privately via GitHub security advisories for this site's repository. A security.txt file is published at /.well-known/security.txt. Please do not open public issues for security reports.

Note: this address is for the website only. Vulnerabilities in KeepKey products should go to KeepKey's own security process, not to this publication.

How the publication handles vulnerability information

  • Essays discussing vulnerabilities rely on information that is already public or already disclosed to the affected vendor.
  • The publication does not release proof-of-concept exploit detail beyond what responsible parties have published.
  • If this publication ever receives non-public vulnerability information, it will be routed to the affected vendor's disclosure process before any reporting decision is made.
  • Coverage of incidents distinguishes confirmed facts from vendor claims and from speculation, per the editorial standards.