As an advocate for "Governance-as-Code" and an ISO 42001/27001 Lead Auditor, I take the security, privacy, and deterministic reliability of these software and AI governance prototypes very seriously.
作為「代碼即管治」的倡導者及 ISO 42001/27001 領先審計師,我極度重視這些軟體及 AI 管治原型的資訊安全、私隱保護及決定性可靠程度。
We encourage responsible reporting of any security flaws within this project, including but not limited to:
我們鼓勵負責任地回報本專案的任何安全缺陷,包括但不限於:
- P2P & WebRTC Security (點對點連線安全): Potential signaling hijack, data packet tampering, or unauthorized room eavesdropping. (WebRTC 信令劫持、封包篡改或未授權房間監聽)
- Data Leakage & Privacy (隱私與資料外洩): Potential leakage of client-side cache, localStorage, or unauthorized device fingerprinting. (本地快取外洩或未授權裝置指紋追蹤)
- Deterministic Logic Bypasses (規則確定性繞過): Flaws allowing state tampering, score manipulation, or bypassing referee lockouts. (允許竄改比分狀態或繞過裁判鎖定權限的邏輯漏洞)
- Client-Side Vulnerabilities (前端安全漏洞): Cross-Site Scripting (XSS), Content Security Policy (CSP) bypasses, or Service Worker cache poisoning. (XSS 跨站腳本攻擊、CSP 繞過或 Service Worker 快取投毒)
DO NOT open a public issue for security vulnerabilities. Public disclosure before a patch is available puts live tournament systems at risk.
請勿在公開的 Issue 區塊提交安全漏洞。 在修補程式釋出前公開漏洞,將危及實時賽事系統的運行安全。
Please report any security or compliance vulnerability privately via direct message on LinkedIn:
請透過 LinkedIn 訊息私下回報任何安全或合規漏洞:
👉 Jacky Law - LinkedIn
- You will receive an acknowledgment of your report within 72 hours. (您將於 72 小時內收到回報確認)
- We will provide a timeline for triage and remediation based on the severity of the identified risk. (我們將根據風險嚴重程度,提供分類與修復的時間表)