Normale Ansicht

  • ✇
  • How to handle a responsible disclosure you get from me?
    (this is mostly cribbed and then adjusted to me and my style from https://blog.literarily-starved.com/2025/06/how-to-handle-a-responsible-disclosure-you-get-from-me/. Thank you Martin for giving me the go-ahead!)Let’s assume you run an IT service or deliver some kind of device to customers, and you receive a report from me informing you about a security problem in your service or device. This can —and has—happened to some of the best in the industry. So, you’re not alone.Now you’re wondering: Wh

How to handle a responsible disclosure you get from me?

28. Juli 2026 um 10:23
How to handle a responsible disclosure you get from me?

(this is mostly cribbed and then adjusted to me and my style from https://blog.literarily-starved.com/2025/06/how-to-handle-a-responsible-disclosure-you-get-from-me/. Thank you Martin for giving me the go-ahead!)

Let’s assume you run an IT service or deliver some kind of device to customers, and you receive a report from me informing you about a security problem in your service or device. This can —and has—happened to some of the best in the industry. So, you’re not alone.

Now you’re wondering: What should you do with this disclosure?

Huzzah: This post is here to guide you through the process.

Let’s start with what’s bad about me reporting such a thing:

  1. Most importantly: There is a very high probability that you (or a close supplier) have a somewhat serious problem. I don't nitpick and I only act when I see something I deem serious in some way or another.
  2. I will have no hope, but also hold you to high standards. I’m investing my spare time because I believe the issue is serious enough to warrant it. I might stop interacting with you, but I will ring bells to get someone's attention — starting small, but escalating quickly if needed.
  3. It is very likely that relevant authorities will be informed in parallel. I believe authorities can only act if they are aware of problems. So, I inform them — even if they don’t act in most cases.

Let’s continue with what’s good about me reporting such a thing:

  1. Fixing the issue will most likely save you money and prevent far bigger trouble in the future.
  2. I don’t want any money. My motivation is civic responsibility, not income. So you don’t need to open your wallet.
  3. I didn’t “hack” your system. I won’t attempt to hack anything, I'm not even that technical anymore. Your problem is most likely an obvious and embarrassing one — which is good, because that usually means it’s easy to fix.
  4. I don’t want to hurt you. My goal is to fix the problem, not to damage your reputation. This might happen anyway if you don’t fix the problem on your side.

What you shouldn’t do?

Some actions will only cause you more pain in the long run:

  1. Ignore me: As mentioned above, I will use increasingly large and loud bells to get attention. This will draw more eyes to your problem, and probably not in a good way.
  2. Threaten me: Attempting to silence me with threats (typically from your lawyers) won’t improve my mood nor resolve anythig. It’s very unlikely I’ll feel seriously intimidated, mostly because I firmly know and can prove that it wasn't me who did something wrong.
  3. Ask me to sign an NDA: I report what I report. I won’t sign an NDA. There’s no upside for me — it only restricts my ability to push for a fix.
  4. Refer me to a bug bounty platform: These often require signing NDAs (see above), and I have no interest in joining yet another platform. I don't want your money. Bug bounty programs don’t help my mission — unless they work via something as simple as sending an email to a listed address.

What can you do beforehand?

There’s one thing you can do in advance that will make such events much less painful:

➡️ Publish a security.txt file compliant with RFC 9116 at all your services.

Having this file means:

  • I assume (initially) that you take security seriously.
  • I’ll use the contact you specified to alert you.

You save everyone time and effort — which I appreciate.

The other thing you can do is to prepare procedures to work with such disclosures. Make sure that any possible input channel of your organization knows how to proceed if such a disclosure arrives. It won’t do any good if you have a security.txt but the message gets ignored because one person is on vacation.

So how should you reply?

I recommend that your reply addresses the following points:

  1. Confirm receipt and establish a channel or contact for further communication.
  2. Reflect your view of the analysis: severity, impact, scope.
  3. Describe the next steps and a timeline.

Example of a near-perfect reply

Such a message would make me very happy:

Thank you for your disclosure. We have opened ticket #123456 to track this issue. You can contact us at incident@example.org for status updates or to provide new information.

We believe this vulnerability affects all customers using service X, especially group Y. We have identified the core problems as Z1 and Z2. We currently rate the severity as (your rating).

To address this, we need to resolve Z1 and Z2 by (your measures). This will take some time, and we can’t give a fixed timeline yet. However, we intend to implement a mitigation in service X within (number of days).

Unless you set an unreasonable timeline, I’ll leave you alone for that period.

My experience with such disclosures

Unless you’ve planned ahead, you very likely will fail to meet my expectations.

Footnotes

  • My disclosure may trigger other legal implications for you. You may need to inform customers, shareholders or other relevant groups. That is your task. I epxect you to know and follow your obligations.
  • You canot prevent me from writing a publicly available after action report. But you have great influence on how professional you look in it.
  • I deeply dislike organisations that fix the problem, but do not communicate (neither to me or the public).
  • My disclosures should be very easy to distinguish from the AI slob you get on other channels. I’ll try to make identifying the problem and severity as easy as possible.
  • ✇
  • Raiders of Arismyth - another year later...
    Last year in August, I declared the rules of my new own RPG to be done.Hah.Turns out, I still had a few ideas and thoughts in me:I tinkered with how Armour and Shields workThe whole system moved from "here's a skill list with lots of written dependencies" to having all the skills and spells arranged in hexmaps. If things are adjacent to each other on those hexmaps, you can learn them, done.Incidentially, that makes for nicer looking character sheets too, as I found out even with my mediocre layo

Raiders of Arismyth - another year later...

09. Juli 2026 um 15:19
Raiders of Arismyth - another year later...

Last year in August, I declared the rules of my new own RPG to be done.

Hah.

Turns out, I still had a few ideas and thoughts in me:

  • I tinkered with how Armour and Shields work
  • The whole system moved from "here's a skill list with lots of written dependencies" to having all the skills and spells arranged in hexmaps. If things are adjacent to each other on those hexmaps, you can learn them, done.
  • Incidentially, that makes for nicer looking character sheets too, as I found out even with my mediocre layouting skills
  • and as a result, I regrouped and removed a bunch of skills. Partially because I realised that there was an overlap, partially because I noticed that for some, I never asked for dice rolls anyway. It feels unfair to ask people to spend advancements for things they never use.

As there was a NordCon between the last blogpost and this one, where I met up with lovely people and talked at length at them about the game, I pressed two people with more design chops into service: Wiebke and Julie.

Julie is busy with creating illustrations for explaining rules and adding interesting views of the various bestiary entries.

And Wiebke has created very lovely character sheets for the game, that fully embrace the "medieval utilitarian" look I hope to go for, and also make the hexmaps pretty. Head over to the game page to check them out!

I am tempted to say now that I'm finished, but I'm probably not kidding anyone. There's at least a few more monsters to write about, I might also add to or revise the starting equipment table, and once I find a good and proper editor, I expect a lot of the text to undergo some changes too.

Nonetheless, the moments where playtesters ask me to change things after a session are definitely gone, so I do think that the bones of the game are there and set now.

And those bones... those bones are beautiful. At least to me.

  • ✇
  • Kinopolis? Lieber nicht mehr
    Wir waren kürzlich im Kino, und weil das Savoy (unser Stammkino) schon recht ausgebucht war, versuchten wir mal das Kinopolis in der HafenCity. Die Buchungswebseite versprach zwar nicht wörtlich, aber schon vom Eindruck und den Schlagwörtern her (Bar, Relax-Sessel, etc.) ein Erlebnis wie das Odeon in London.Wer das nicht kennt: Das Odeon ist ein, ahem, Luxus-Kino. Man sitzt in Sesseln, die sich quasi komplett in Liegen umwandeln lassen, angeordnet in Zweiergrüppchen mit viel Platz zur nächsten G

Kinopolis? Lieber nicht mehr

06. April 2026 um 11:43
Kinopolis? Lieber nicht mehr

Wir waren kürzlich im Kino, und weil das Savoy (unser Stammkino) schon recht ausgebucht war, versuchten wir mal das Kinopolis in der HafenCity. Die Buchungswebseite versprach zwar nicht wörtlich, aber schon vom Eindruck und den Schlagwörtern her (Bar, Relax-Sessel, etc.) ein Erlebnis wie das Odeon in London.

Wer das nicht kennt: Das Odeon ist ein, ahem, Luxus-Kino. Man sitzt in Sesseln, die sich quasi komplett in Liegen umwandeln lassen, angeordnet in Zweiergrüppchen mit viel Platz zur nächsten Gruppe, Tabletthaltern damit man die Snacks nicht auf dem Schoß balancieren muss. Vorne gibt es eine richtige Bar, eine Garderobe, und so weiter.

Das Kinopolis ist das... nicht so.

Die Relax-Sessel sind tatsächlich einfach nur die erste Reihe, die aus der Puren Not [tm] heraus als Liegen ausgeführt ist, damit man keinen steifen Hals bekommt. Konsequenterweise lassen sie sich auch nicht verstellen, sondern sind eben einfach nur Liegen.

Die Sicht auf die Leinwand ist dennoch eher bescheiden, man sitzt einfach zu nah dran, und alles ist irgendwie verzerrt. Dafür dann auch noch den "Relax-Sessel-Aufpreis" zu verlangen ist schon unverschämt.

Ton- und Bildqualität waren ansonsten 1a, da kann man nicht meckern.

Und der Rest vom Kino"erlebnis"?

Naja. Das geht damit los, dass das Kinopolis in der Westfield Mall der HafenCity ist. Das ist eines der seelenlosesten Konsumgebiete der Stadt, wenn Ihr mich fragt. Am Wochenende natürlich voll von Pinnebergern[^1] und Touristen.

Die Läden sind die bekannten Ketten, und man muss sich erst durch den Food Court quälen, bevor man am Kino selbst ist.

Das ist dann auch weniger "premium" und mehr "wir maximieren den Durchfluss mit minimalen Personaleinsatz": Bildschirmkioske überall, und die Snackbar hat quasi nur Popcorn und Nachos, weil das eben einfach en gros portionier- und verkaufbar ist.

Mittendrin wollte dann noch wer aufs Klo und hat den Notausgang statt den richtigen Ausgang genommen. (Dies Schilder sind an beiden die gleichen) Und damit den Türalarm ausgelöst, der dann so 5-10m vor sich hin piepte, bis mal wer vom Personal vorbeischaute..

Und jetzt der Kicker: Ich hab die Karten online gekauft. Und bei solchen Abschlüssen gebe ich NIE die Erlaubnis für Newsletter oder ähnliches. Ein Kundenkonto hab ich auch nicht angelegt.

Dennoch kam zwei Tage nach dem Kinobesuch erst mal eine "hey, kannst Du uns bewerten?" Email und heuer dann auch nochmal der allgemeine Filmempfehlungs-Newsletter.

Bei Betätigung des "Abbestellen"-Knopfs wird dann auch gezielt darauf hingewiesen, dass man damit genau nur diese Kategorie von Newsletter abbestellen würde. Welche es sonst noch gibt, und ob man die bekommen würde verrät das Tool einem nicht. Das Dark Pattern hier ist, dass die Firmen hier gefühlt drölfzig verschiedene obskure Kategorien haben, und auch gerne mal neue hinzuerfinden. Denkt an so Späße wie "Action-Filmempfehlungen" vs "Filmempfehlungen voller Dynamik".

Das formale DSGVO-Schreiben zwecks Datenauskunft und -löschung ist raus. Die sehen mich nie wieder.

[^1]: Die von eingeborenen Hamburgern abfällige Bezeichnung für das Landvolk aus dem Speckgürtel. Sorry Pinneberg! :)

  • ✇
  • Once more onto the breach!
    I did like WriteFreely in general, but there were a few drawbacks:Very limited layoutno comment functionality at allnot really a good support for displaying tagsand a some minor quibblesOver the weekend, I finally got Ghost to work properly, and the Discourse integration to boot. There were a few things to sort out though:contrary to instructions found at ghost.org/integrations/discour, Discourse does not provide a snippet of code. Well, I'll just copy that from the page there, eventually, it wo

Once more onto the breach!

29. März 2026 um 22:07
Once more onto the breach!

I did like WriteFreely in general, but there were a few drawbacks:

  • Very limited layout
  • no comment functionality at all
  • not really a good support for displaying tags
  • and a some minor quibbles

Over the weekend, I finally got Ghost to work properly, and the Discourse integration to boot. There were a few things to sort out though:

  • contrary to instructions found at ghost.org/integrations/discour, Discourse does not provide a snippet of code. Well, I'll just copy that from the page there, eventually, it worked.
  • the trailing / in the URL for the discourseUrl super important and mandatory. That should be spelled out.
  • if you don't tell Discourse to really server everything over https, you'll get mixed-content-security errors instead of an integration
  • and of course, I had to add aliases for noreply etc. to my account at the mailserver, so it won't reject things.

So, in the end, this now works, and I can update the stacks through Portainer too. I had to throw away the Discourse install away though and recreate it because the Marius Hosting howto locks the version at 3.5.o instead of "latest", and I didn't realise that until it was too late.

Mostly, I am happy that there is a comment functionality again, and maybe I'll use the forum for some other things too in the future. I do guess that Raiders of Arismyth could use one - need to look at the Wiki functionality of Discourse.

❌