Working with TKDS support

I found a security vulnerability — how do I report it?

Quick answer

Email security@tkdsmedia.com and ask for a PGP key before you send any details. Keep the first message short, and don’t post the issue anywhere public.

Check this first

  1. 1
    Ask for a key

    Email security@tkdsmedia.com saying you have a vulnerability to report, and ask for a PGP key. Leave out how it works.

  2. 2
    Send the details encrypted

    Once you have the key, send the details encrypted: what’s affected, how to reproduce it and what an attacker could do.

  3. 3
    Keep it private

    Don’t describe the issue in a public post, a comment or an ordinary support ticket.

Which route to use

What you haveWhere it goesFirst step
A weakness in MediaCore2 itselfsecurity@tkdsmedia.comAsk for a PGP key before sending details.
A staff account on your platform you think is misusedYour own administrators, then a ticketDelete or edit the account in Studio → Management → Staff Members, and check the activity log for its Signed in entries.
A viewer account taken overYour staff, then a ticket at /help/ticket if it continuesType a New password (optional) on the account in Studio → Management → Users and save. Ask the viewer to sign out any device they don’t recognise.
A suspicious email claiming to be from your platformA ticket at /help/ticketAttach a screenshot. Don’t click its links.

The full guide

Did this guide help?