Reporting a problem
Email security@tiny-bits.com. If that address bounces for any reason, use support@tiny-bits.com and put "security" in the subject line. Tell us what you found, how to reproduce it, and what an attacker could do with it. A rough note that we can act on is worth more than a polished one that arrives a month later. Write in English if you can; we will manage otherwise. Please do not open a public issue, post it publicly, or demonstrate it against anybody else's machine before we have had a chance to fix it.
What we commit to
• We acknowledge every report within 3 working days. If you have not heard from us by then, assume the mail went astray and send it again. • We tell you within 10 working days whether we can reproduce it and what we intend to do. • We keep you informed while we work, and we tell you when the fix ships. • We credit you by whatever name you choose, on this page, unless you would rather we did not. We are a very small company. These are commitments about answering you promptly and honestly, not about a fix arriving overnight.
Safe harbour
If you are acting in good faith under this policy, we will not pursue legal action against you, and we will not ask anyone else to. Acting in good faith means: you work only against your own devices and your own installation, you do not access, change or keep anybody else's data, you do not degrade a service anybody else is relying on, and you give us a reasonable chance to fix the problem before you publish. If you are unsure whether something is in bounds, ask us first. We would much rather answer a question than receive an apology.
In scope
• Tiny Pad Server, the application for Linux, macOS and Windows. Its pairing, its encrypted session, its network handling, the input it injects and the screen region it captures. • The Tiny Pad app for iPhone and iPad. • tiny-pad.com, this site. The interesting parts are the ones that cross a trust boundary: anything reachable before pairing completes, anything that lets a device do more than the pairing it holds should allow, and anything that turns input relay into arbitrary code execution.
Out of scope
• Denial of service, traffic floods, and anything whose method is volume. • Social engineering of us, our users, or anyone else. • Physical attacks, and attacks that need an already-unlocked device in hand. We say plainly in our privacy policy that anyone holding your unlocked iPhone can control the computer it is paired with; that is the design, not a flaw. • Findings from automated scanners with no demonstrated impact. • Missing hardening headers on this site, absent a concrete attack. • Third-party services we do not run, including Apple's App Store.
There is no bounty
We do not pay for vulnerability reports. We are saying so plainly so that nobody spends their time on the assumption that we might. What we do offer is a fast, human answer, credit on this page if you want it, and a fix.
security.txt
The machine-readable version of this page is at /.well-known/security.txt, in the format described by RFC 9116.
Acknowledgements
Nobody yet. This section will list the people who have reported a security problem in Tiny Pad and asked to be named.