Reporting a security issue.
If you've found a way past the encryption, or a hole in this website, I want to hear about it, privately.
How to report it
Email security@considus.com. Please keep it private, so don't open a public issue or a pull request on GitHub.
Tell me what you found, how to reproduce it, which version, commit or page it affects, and what it lets an attacker do. If email isn't an option for you, the support form reaches me too.
What happens next
I'll acknowledge your report within 3 business days and keep you posted while I look into it.
This is coordinated disclosure, so please give me a reasonable amount of time to ship a fix before you make it public. You're welcome to the credit once it's out, or to stay anonymous, whichever you'd prefer.
What's in scope
Catchlight encrypts your Takes on your device, with a key derived from your Privacy phrase that never leaves it. The app itself has no backend and no analytics, so if the encryption fails there's nothing else standing between someone's Takes and whoever is looking.
These are in scope, and anything you find in any of them comes to the same address:
- The Catchlight app for iPhone, and how it protects what it stores on the device.
- Catchlight for Mac, and how it stores, protects and syncs Takes on the Mac.
- Catchlight Core, which holds the cryptographic design, key management and the file-based sync format.
- Catchlight AppleStorage, which covers the database and what it leaves readable, file protection, backup exclusion, the wordlist, and the Keychain items that hold the master key and the Privacy phrase.
- This website, catchlight.app, and the code that runs on its server, such as the mailing-list sign-up and the support form.
Generally out of scope, anything that needs a jailbroken or otherwise compromised device, or physical access to a device that's already unlocked. Social engineering and denial of service are out too, along with findings in third-party platforms like Apple or whichever cloud provider the user picked, because those aren't mine to fix. Flaws in the services this website runs on (Cloudflare, which hosts it, and MailerLite, which runs the mailing list) are out as well, as I don't control either of them.
For the website, a report that the site skips a best practice, with no demonstrated way to do harm, is out of scope too. That covers missing security headers, the domain's email settings (SPF, DKIM and DMARC), clickjacking on a page with no sensitive actions, and anything else of the same kind.
Safe harbour
You won't face legal action from me or from Considus for research done in good faith, so long as you avoid violating anyone's privacy, avoid destroying data, and follow this policy.
Which versions get fixes
The main branch of each repository gets security fixes. So does the latest tagged release of Core and AppleStorage, which is the version the apps pin, and so will each app's current release once it has one.
Each repository carries the policy for its own part in a SECURITY.md, and the source is on GitHub at Catchlight-iOS, Catchlight-MacOS, Catchlight-Core and Catchlight-AppleStorage.