This SDK runs on devices belonging to people who agreed to share bandwidth, and nothing else. A bug that lets it do more than that is serious, and we would much rather hear about it from you than from a user.
Email security@sterr.network with what you found, how to reproduce it, and what you think the impact is. Please do not open a public issue.
We will acknowledge within 3 working days and keep you updated while it is being fixed. If you would like credit in the release notes, say so; if you would rather not be named, that is fine too.
Please do not test against live devices you do not own. The coordinator repo runs the whole network locally in one command — that is the right target.
In rough order:
- Traffic carried without consent, or continuing after it is withdrawn.
- A customer reaching a device's local network (a private, loopback or link-local address) through the tunnel.
- One device assuming another's identity, or a partner attributing another partner's devices to itself.
- Reading, altering or leaking the host app's or the user's own data.
- A device's exit IP reaching a partner or a customer.
- Anything that lets a customer make a device open ports outside the allowed set.
- Remote code execution, or a crash reachable by an unauthenticated peer.
- The fact that a device's IP address is visible to the sites it connects to. That is what an exit node is; it is disclosed, and it is why consent is required.
- That
consent: truein the handshake cannot be cryptographically verified. Consent happens on the device, so it is a contractual gate. A partner that lies is in breach of its agreement and of privacy law — the SDK cannot fix that and does not pretend to. - Reports generated by a scanner with no demonstrated impact.
The latest release. This is young software; there is no back-porting yet.