Relatar uma vulnerabilidadeReport a vulnerability
Achou uma falha de segurança no Blackhold — na imagem, no site ou no caminho de atualização? Conte para nós em primeiro lugar, em privado. Nós confirmamos o recebimento, corrigimos, e creditamos quem ajudou.Found a security flaw in Blackhold — in the image, the site, or the update path? Tell us first, in private. We acknowledge receipt, fix it, and credit whoever helped.
Cifre o seu relato com a nossa chave pública — é a mesma chave que assina as imagens do Blackhold, que você encontra na página de download e embutida na própria imagem. Assim o conteúdo só é lido por nós.Encrypt your report with our public key — it's the same key that signs Blackhold's images, found on the download page and embedded in the image itself. That way only we can read the contents.
O que incluir no relatoWhat to include
- Passos para reproduzir — o mais objetivo possível.Steps to reproduce — as concrete as possible.
- A versão do Blackhold e o hardware, se for relevante.The Blackhold version and the hardware, if relevant.
- O impacto que você enxerga: o que um atacante ganharia.The impact you see: what an attacker would gain.
- Uma prova de conceito, se você tiver — ajuda muito a priorizar.A proof of concept, if you have one — it helps a lot to prioritize.
Divulgação coordenadaCoordinated disclosure
Trabalhamos com divulgação coordenada, o padrão da área:We work with coordinated disclosure, the industry standard:
- Você reporta em privado, antes de tornar público.You report privately, before going public.
- Confirmamos o recebimento em até 72 horas.We acknowledge receipt within 72 hours.
- Investigamos, corrigimos, e combinamos com você a data da divulgação.We investigate, fix, and agree with you on the disclosure date.
- Damos crédito a quem reportou, salvo se você preferir anonimato.We give credit to the reporter, unless you prefer to stay anonymous.
Não movemos ações legais contra pesquisa de boa-fé feita dentro deste processo.We take no legal action against good-faith research done within this process.
EscopoScope
Dentro: a imagem do Blackhold, o site blackhold.org e o caminho de atualização. Fora: engenharia social de mantenedores, serviços de terceiros, ataques que exigem hardware já comprometido, e as limitações já conhecidas do nosso modelo de ameaça — essas não são falhas, são fronteiras que já assumimos.In scope: the Blackhold image, the blackhold.org site, and the update path. Out of scope: social engineering of maintainers, third-party services, attacks that require already-compromised hardware, and the known limitations of our threat model — those aren't flaws, they're boundaries we already own.
Avisos de segurançaSecurity advisories
Nenhum publicado até agora. Quando houver, eles aparecem aqui — numerados, datados e com a versão corrigida. A ausência é honesta: o projeto é novo, não auditado à exaustão, e a página de limitações diz o que ainda não cobrimos.None published so far. When there are, they'll appear here — numbered, dated, and with the fixed version. The absence is honest: the project is new, not exhaustively audited, and the limitations page says what we don't cover yet.
Atualizado em 29 de agosto de 2026.Updated August 29, 2026.