• Buy
  • Prices
  • Coins
  • Earn
Login
Start now

Responsible disclosure

We consider the security of our systems a top priority. But, no matter how much effort we put into system security, vulnerabilities could still be present.

If you discover a vulnerability, we would like to know about it so we can take appropriate measures as quickly as possible. We would greatly appreciate your help in protecting our clients and systems.

Please follow the steps below:

  • E-mail your findings to responsibledisclosure@weareblox.com. Encrypt your findings using our PGP key (you can find it at the bottom of the page) to prevent this critical  information from falling into the wrong hands.
  • Do not take advantage of the vulnerability or problem you have discovered, for example by downloading more data than necessary to demonstrate the vulnerability or deleting or modifying other people's data.
  • Do not reveal the problem to others until it has been resolved.
  • Do not use attacks on physical security, social engineering, distributed denial of service, spam or applications of third parties.
  • Provide sufficient information to reproduce the problem, so we will be able to resolve it as quickly as possible. Usually, the IP address or the URL of the affected system and a description of the vulnerability will be sufficient, but complex vulnerabilities may require further explanation for instance screenshots about the steps that are needed to reproduce the vulnerability or which software is being used to find the vulnerability.

What we promise:

  • We will respond to your report within 5 business days with our evaluation of the report and an expected resolution date.
  • If you followed the instructions above, we will not take any legal action against you in regards to the report.
  • We will handle your report with strict confidentiality, and we will not pass on your personal details to third parties without your permission.
  • We will keep you informed of the progress towards resolving the problem.
  • In the public information concerning the problem reported, we will give your name as the discoverer of the problem (unless you desire otherwise).
  • As a token of our gratitude for your assistance, we offer a reward for every report of a security problem that was not yet known to us. The amount of the reward will be determined based on the severity of the leak and the quality of the report. The minimum reward will be €50 in bitcoin.

We strive to resolve all problems as quickly as possible, and we would like to play an active role in the ultimate publication of the problem after it is resolved.

Trivial security issues:

Security issues with the following properties will not be identified as vulnerabilities that need to be reported. If a combination of such issues creates a security vulnerability we would like to hear it. The issue will be examined and given the appropriate reward.

  • General error messages regarding application or server errors
  • HTTP 404 and other non-HTTP 200 error messages
  • The accessibility of public files and directories (as robots.txt)
  • CSRF issues on parts of the site that are available to anonymous users
  • CSRF issues that have no (serious) undesirable consequences for users
  • Trace HTTP functions that can be active
  • SSL attacks like BEAST, BREACH, Renegotiation
  • SSL Forward secrecy not used
  • Anti-MIME Sniffing header X-Content-Type functions
  • The lack of HTTP security headers
  • The presence of HTTPS Mixed Content Scripts / error messages

PGP key:

-----BEGIN PGP PUBLIC KEY BLOCK-----mQINBGRrHMsBEAClPbGlXHpbNa8XjenXEFcwgNREJZELL8lQUHGk+c2ssZsrrDGR
pnGxeE5xejAvFco1UmBh2cPN45MfPTtvZ8O2UY5L22SZK0ms4fuKHfumIrE+rPT9
Sr0Lsq6C1Pz83A5soDtRhiGZyt9w294OAn/9cq3q1Dhu+fl6nImAGBphRM72+D1N
cJHk9As/CWEhdth8WV7Y6KaJ3qS6aiOcbR6wCk5QXqg8H4BaJ36YrqLCedqDfM59
ULIC2TlRmVd3hcOhwAL7NgQ+ddf/wKEVtGcVNCctOHkiNpjsRHAV1sJPi0GLtFXw
vPa15y6EQANOOiqmJgkqGKQ7eKE/AGDZH0SYafoPuZlp6CcezTIjMxA8Gqc6EUjx
eosdJ0Z3C0TVQxwLnfGpjrA8u/neJLMY6lUN+bKVSr607nunpOhItnMv4NwhfgvO
75H6wKoCoGRtAQyVWdGeaQhTAcBjDkVqjUZZNggM6cFRgmp7ttIK3WKFBgUnpeU6
uMFTPZ4eEUm6srgo+MRmSbcDQU2PF8njrRPq+8/E006X4Pjuw5qB6Rjd2CluhD4j
o0qjrSGFeAd/x8WEDI6JoC1yqfERiRT4dd6Hcdrg8nZpMT6FpiIokrDfc9p3yxnt
JdClCUZNstbwdSR1BUXbaubv/G2FhGlWrntbroupjoOQ4qwC9uWCbgWIfQARAQAB
tEZSZXNwb25zaWJsZSBEaXNjbG9zdXJlIEJUQyBEaXJlY3QgPHJlc3BvbnNpYmxl
ZGlzY2xvc3VyZUBidGNkaXJlY3QuZXU+iQJUBBMBCAA+FiEExUO2RhEJjWQ5Mm+p
Xef331GIgM4FAmRrHMsCGwMFCQeGH2AFCwkIBwIGFQoJCAsCBBYCAwECHgECF4AA
CgkQXef331GIgM7a8A//cIlwl7qitW6GRe/vEoVvJlgFb2eHzaJVMB6tdv9yfjSv
mcQUmrdPkSQG/bnrF2VFbuft6fOjaJ/xkS0kCMBJlEu1q61QDIwrV3+el85PaIJj
/+ITCGVMu4K035IgG6eQRas33OnuVT5EoOPCMJM7ZToCIvrVYGbRnkY47nnKjcGN
ounGoBGU1eSPrhQnMHDPhsohWjaA8n79kHxjovPW/UMh5IMFSmmjVerKuNFIWafi
e6m1Z5Dc33QqA6odUtmBi2khMye9H19CZFYzNjSUwvnw2P58ir6pamAqrFT0uNlG
7foQV+Ml3vbybK35XakLpMK1wQ2yjMbVzMbAybD1lq4FpktOB5rtUPITldbkpM90
qC9O5b7tyS6fu2tnhwNML69VUYlnQKAPBosB9U26XDh6Zx2h7jV3WFIpn2L1PtTs
I3w8PXGxl3SCDX2vudKpvff93DYPP4f2k36r2lIdFIvzmTOq4nr+C2AW9qVDB3U8
l5/88oYN0C9SmvQFeRW3eQ/011PnZ2BIHBwmvGA0k/UP2f/2D7TVahmcrrz88vVi
UvwbKoEInUEENCAJUmiZJdUnhjJR3KiKBJ1VgU1PYJQ8jUreiyvh7nZnyHp0kjrW
lt6k8WqmRKDAu919MJhAlsCDKq7+jNH+fhTdM+mT7rDjZ2i6Y4YbQzC3pfBGt/a5
Ag0EZGscywEQALJPBMwP1cE4VCtUDQlsshsZ/N/yDvC4AjCpliFmr5sGpkZEtlLE
QzIaSqBRGXLh2PMsh6K93xA53OQ2NTOsu8OOK9+KSsNE3XdleOQdRCHQ/Kswsby2
+mWXckNzeRi535P+tIgcWvFbpsYlZyxpaPzilXwrRS3lUIhA8iNHq72XC5RNqfiY
B/m1XN6HntdrwR77gMY2kaB0VLsOYmvfbh7CiPSEcrrFdwzLaJwODwtBVBFM8wMF
1+8TX47C+9FHyOKjg0PDgrJCVu7Y1054CQQWEofsWcpEOAPjW/0+67iFCmmeTtc6
SsxwUWYyjfkTuz57Vnw6MHHy1vldcRwOZUDRSPI/M+3/hHU1WKzRRsRyYKTh/YSD
xpC042Cs6NUmrxPmmjFzKzt3YaeqE3TFvqjNIHTXfIHB4FtAFQc/wNhszPcwzwIv
d1Ds1CWvpIyID/DCTa6+5+LFOZFbhmilcFoY6Lnc6J02QQWfXvxZ8goVfVrsrW+8
baosBHgss/6LKK9ocVEl0UbKeHGvIAgO78Y5Q6SmlCptGKk2phTMYMzFWVuv+tf2
sGC535rzGRwA88wNDdMhvcCWljyG3DbbL0laOMDOl8oE6P0vcH06wuo3CJxwcZN/
zpAdF0kl4qPvxXca5fjcXbcKLDx8nKno5aqJNVpXDgVtZQf0MCO9/H8jABEBAAGJ
AjwEGAEIACYWIQTFQ7ZGEQmNZDkyb6ld5/ffUYiAzgUCZGscywIbDAUJB4YfYAAK
CRBd5/ffUYiAziKWEACjwzZ+FxN/dCnSn61TuKcXNNPk/SzmlJsvA8C+0k9V7n1Z
FJgNI+d1GwxrWL498/PyCVVOvQZeRyE1inpxE/2IkY27mGFw+xGUySL2Ts5XRw7S
TO5ccCRjRmozGIrzLQO/+eJdB7vOcS/jmcjkPcrJjl6mi3bX9XsjfFXj9JxBAt4T
PH2oMt3mASSJCbqK+3OyY6QRHoQhMiTnGFz0rgBbeSS0/qRAfp+G7fUvP7lAfW73
UqZFUQvBZDLZ5VbLx3SY8C4hf1lNqEAdXQKiTWQRWv6YfiZidUPMWCXHQbCH096y
sFP+lyFiZfrmw88TRvO2g0JFPlooTUmUqZPi/570NTSg8AY4msh0eYw03YdcseTz
5GjoliG+I1eeIwGZY42hdnxtmP34qPATbAWtVzu99i96yLJxXnAIt3oxgkywlPnF
lRbCZJWxwpCeRXOAxWSQMnYPqSmM2Sae4I44b6pxXlC/0r6wdvbDUVPRq/eeHBkM
Vf5e5FSHTCkgyCs4m4pj95/aGtHDV2a79r/kNC4o21SYO1taC3exiARwwpkzCH7J
8YF9kwBYtGZrCB4VxjTddhoJjEB2J4d4CvjMejxkGvUU1WrHW23CC9Mwc6kj13gJ
0KuKSALS7PwZel7hDq2qfoUjQLyWEEhD/3VZF2iPfuFx2X7zOSHBYNO7AVYEoQ==
=RBWN
-----END PGP PUBLIC KEY BLOCK-----