Confiança · segurançaTrust · security

Relatar uma vulnerabilidadeReport a vulnerability

Achou uma falha de segurança no Blackhold — na imagem, no site ou no caminho de atualização? Conte para nós em primeiro lugar, em privado. Nós confirmamos o recebimento, corrigimos, e creditamos quem ajudou.Found a security flaw in Blackhold — in the image, the site, or the update path? Tell us first, in private. We acknowledge receipt, fix it, and credit whoever helped.

ContatoContact
Chave pública · OpenPGP (Ed25519)Public key · OpenPGP (Ed25519)
5C8B 577E E0B7 602B F569 7F53 CA15 8D55 3B9B 9750

Cifre o seu relato com a nossa chave pública — é a mesma chave que assina as imagens do Blackhold, que você encontra na página de download e embutida na própria imagem. Assim o conteúdo só é lido por nós.Encrypt your report with our public key — it's the same key that signs Blackhold's images, found on the download page and embedded in the image itself. That way only we can read the contents.

O que incluir no relatoWhat to include

Divulgação coordenadaCoordinated disclosure

Trabalhamos com divulgação coordenada, o padrão da área:We work with coordinated disclosure, the industry standard:

Não movemos ações legais contra pesquisa de boa-fé feita dentro deste processo.We take no legal action against good-faith research done within this process.

EscopoScope

Dentro: a imagem do Blackhold, o site blackhold.org e o caminho de atualização. Fora: engenharia social de mantenedores, serviços de terceiros, ataques que exigem hardware já comprometido, e as limitações já conhecidas do nosso modelo de ameaça — essas não são falhas, são fronteiras que já assumimos.In scope: the Blackhold image, the blackhold.org site, and the update path. Out of scope: social engineering of maintainers, third-party services, attacks that require already-compromised hardware, and the known limitations of our threat model — those aren't flaws, they're boundaries we already own.

Avisos de segurançaSecurity advisories

Nenhum publicado até agora. Quando houver, eles aparecem aqui — numerados, datados e com a versão corrigida. A ausência é honesta: o projeto é novo, não auditado à exaustão, e a página de limitações diz o que ainda não cobrimos.None published so far. When there are, they'll appear here — numbered, dated, and with the fixed version. The absence is honest: the project is new, not exhaustively audited, and the limitations page says what we don't cover yet.

Um resumo legível por máquina deste contato está em security.txt. Preferimos divulgação coordenada: reporte em privado, dê tempo para a correção, e divulguem juntos.A machine-readable summary of this contact is at security.txt. We prefer coordinated disclosure: report privately, allow time for a fix, and disclose together.

Atualizado em 29 de agosto de 2026.Updated August 29, 2026.