Working with TKDS support
I found a security vulnerability — how do I report it?
Quick answer
Email security@tkdsmedia.com and ask for a PGP key before you send any details. Keep the first message short, and don’t post the issue anywhere public.
Check this first
- 1Ask for a key
Email security@tkdsmedia.com saying you have a vulnerability to report, and ask for a PGP key. Leave out how it works.
- 2Send the details encrypted
Once you have the key, send the details encrypted: what’s affected, how to reproduce it and what an attacker could do.
- 3Keep it private
Don’t describe the issue in a public post, a comment or an ordinary support ticket.
Which route to use
| What you have | Where it goes | First step |
|---|---|---|
| A weakness in MediaCore2 itself | security@tkdsmedia.com | Ask for a PGP key before sending details. |
| A staff account on your platform you think is misused | Your own administrators, then a ticket | Delete or edit the account in Studio → Management → Staff Members, and check the activity log for its Signed in entries. |
| A viewer account taken over | Your staff, then a ticket at /help/ticket if it continues | Type a New password (optional) on the account in Studio → Management → Users and save. Ask the viewer to sign out any device they don’t recognise. |
| A suspicious email claiming to be from your platform | A ticket at /help/ticket | Attach a screenshot. Don’t click its links. |
The full guide
Did this guide help?