[{"id":3774040,"new_policy":"\n# Security Stance\n\nSecurity and transparency are top priorities at Chaturbate. Networks are dynamic. The technology, users, data in the systems, risks, and security requirements are ever-changing. Chaturbate knows that security is never perfect and can never be taken for granted. People will discover new ways to intentionally or unintentionally bypass or subvert security.  \n\nTime can expose new vulnerabilities, and the most effective way to counteract these vulnerabilities is to become aware of them quickly and to fix them immediately with rewards for you.\n\n# Reporting Guidelines\n\nSubmitting clear, detailed reports is highly encouraged. Each report should explain one vulnerability in detail, identify its impact, and most importantly include steps or a \"proof of concept\" instructions to reproduce the issue.\n\n*Very low-quality reports, such as those which only contain automated output, will be rejected.*\n\n* Let us know as soon as possible upon discovery of a potential security issue, and we'll make every effort to quickly resolve the issue. \n* Provide us a reasonable amount of time to resolve the issue before any disclosure to the public or a third-party. \n* Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of service. \n* Only interact with accounts you own or with explicit permission of the account holder. \n* Include attachments such as screenshots or proof of concept code as necessary. \n* Disclose the vulnerability report directly and exclusively to us.\n\n# Rewards\n\nPlease see our reward table above.\n\nTo qualify for a reward under this program, you should be the first to report the vulnerability.\n\n# Scope\n\nAt this time, the scope of this program is limited to security vulnerabilities found on Chaturbate and its supporting services. Vulnerabilities reported for other properties may be considered on a case-by-case basis.\n\n# Exclusions \nWhile researching, refrain from: \n* Interfering with other users of the site\n* Spamming \n* Social engineering (including phishing) of staff or contractors \n* Any physical attempts against property or data centers \n* Scripting or other automation and brute forcing of intended functionality\n\n### Denial of Service and Brute Force\nTargeted brute force attacks are permitted to discover incorrect or missing rate limits; however the request rate *must* be under **100 requests per minute** for an endpoint. E.g. checking the rate limit on a password input.\nAdditionally the requests must only be made against your own accounts.\n\nA missing rate limit does not always signify a security issue, only endpoints performing sensitive actions may be considered.\n\nIndiscriminate brute forcing or Denial of Service above the specified rate are not permitted.\n\n### The following reports do not qualify\n\n* Reports regarding using the same email for multiple accounts, this is by design\n* Reports regarding username enumeration\n* Reports about the external_url page \n* Reports about password requirement for changing email, this is commonly misreported\n* Reports against other sites, such as \"stream ripping\" or \"stream capping\" sites\n* Reports that involve manipulating the room user count\n* Reports regarding ability to frame/embed the register and room viewing pages\n* Bugs requiring exceedingly unlikely user interaction\n* HttpOnly and Secure cookie flags\n* Reports of software version disclosure\n* Reporting vulnerabilities that are deemed as accepted risks\n* Bugs that don’t affect the latest version of modern browsers, or browser extensions.\n* Attacks requiring MITM or physical access to a user's device\n* Previously known vulnerable libraries without a working Proof of Concept.\n* Content spoofing and text injection issues without showing an attack vector/without being able to modify HTML/CSS\n\n\n# Safe Harbor \nAny activities conducted in a manner consistent with this policy will be considered authorized conduct and we will not initiate legal action against you. If legal action is initiated by a third party against you in connection with activities conducted under this policy, we will take steps to make it known that your actions were conducted in compliance with this policy. \n\nThank you for helping keep Chaturbate and our users safe! \n","has_open_scope":null,"pays_within_one_month":null,"protected_by_gold_standard_safe_harbor":null,"protected_by_ai_safe_harbor":null,"disclosure_declaration":null,"introduction":null,"platform_standards_exclusions":[],"exemplary_standards_exclusions":[],"scope_exclusions":[],"timestamp":"2026-05-12T14:11:26.749Z"},{"id":3641721,"new_policy":"\n# Security Stance\n\nSecurity and transparency are top priorities at Chaturbate. Networks are dynamic. The technology, users, data in the systems, risks, and security requirements are ever-changing. Chaturbate knows that security is never perfect and can never be taken for granted. People will discover new ways to intentionally or unintentionally bypass or subvert security.  \n\nTime can expose new vulnerabilities, and the most effective way to counteract these vulnerabilities is to become aware of them quickly and to fix them immediately with rewards for you.\n\n# Reporting Guidelines\n\nSubmitting clear, detailed reports is highly encouraged. Each report should explain one vulnerability in detail, identify its impact, and most importantly include steps or a \"proof of concept\" instructions to reproduce the issue.\n\n*Very low-quality reports, such as those which only contain automated output, will be rejected.*\n\n* Let us know as soon as possible upon discovery of a potential security issue, and we'll make every effort to quickly resolve the issue. \n* Provide us a reasonable amount of time to resolve the issue before any disclosure to the public or a third-party. \n* Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of service. \n* Only interact with accounts you own or with explicit permission of the account holder. \n* Include attachments such as screenshots or proof of concept code as necessary. \n* Disclose the vulnerability report directly and exclusively to us.\n\n# Rewards\n\nPlease see our reward table above.\n\nTo qualify for a reward under this program, you should be the first to report the vulnerability.\n\n# Scope\n\nAt this time, the scope of this program is limited to security vulnerabilities found on Chaturbate and its supporting services. Vulnerabilities reported for other properties may be considered on a case-by-case basis.\n\n# Exclusions \nWhile researching, refrain from: \n* Interfering with other users of the site\n* Spamming \n* Social engineering (including phishing) of staff or contractors \n* Any physical attempts against property or data centers \n* Scripting or other automation and brute forcing of intended functionality\n\n### Denial of Service and Brute Force\nTargeted brute force attacks are permitted to discover incorrect or missing rate limits; however the request rate *must* be under **100 requests per minute** for an endpoint. E.g. checking the rate limit on a password input.\nAdditionally the requests must only be made against your own accounts.\n\nA missing rate limit does not always signify a security issue, only endpoints performing sensitive actions may be considered.\n\nIndiscriminate brute forcing or Denial of Service above the specified rate are not permitted.\n\n### The following reports do not qualify\n\n* Reports regarding using the same email for multiple accounts, this is by design\n* Reports regarding username enumeration\n* Reports about the external_url page \n* Reports about password requirement for changing email, this is commonly misreported\n* Reports against other sites, such as \"stream ripping\" or \"stream capping\" sites\n* Reports that involve manipulating the room user count\n* Reports regarding ability to frame/embed the register and room viewing pages\n* Bugs requiring exceedingly unlikely user interaction\n* HttpOnly and Secure cookie flags\n* Reports of software version disclosure\n* Reporting vulnerabilities that are deemed as accepted risks\n* Bugs that don’t affect the latest version of modern browsers, or browser extensions.\n* Attacks requiring MITM or physical access to a user's device\n* Previously known vulnerable libraries without a working Proof of Concept.\n* Content spoofing and text injection issues without showing an attack vector/without being able to modify HTML/CSS\n\n\n# Safe Harbor \nAny activities conducted in a manner consistent with this policy will be considered authorized conduct and we will not initiate legal action against you. If legal action is initiated by a third party against you in connection with activities conducted under this policy, we will take steps to make it known that your actions were conducted in compliance with this policy. \n\nThank you for helping keep Chaturbate and our users safe!\n","has_open_scope":null,"pays_within_one_month":null,"protected_by_gold_standard_safe_harbor":null,"protected_by_ai_safe_harbor":null,"disclosure_declaration":null,"introduction":null,"platform_standards_exclusions":[],"exemplary_standards_exclusions":[],"scope_exclusions":[],"timestamp":"2020-08-26T07:14:17.674Z"},{"id":3593250,"new_policy":"\n# Security Stance\n\nSecurity and transparency are top priorities at Chaturbate. Networks are dynamic. The technology, users, data in the systems, risks, and security requirements are ever-changing. Chaturbate knows that security is never perfect and can never be taken for granted. People will discover new ways to intentionally or unintentionally bypass or subvert security.  \n\nTime can expose new vulnerabilities, and the most effective way to counteract these vulnerabilities is to become aware of them quickly and to fix them immediately with rewards for you.\n\n# Reporting Guidelines\n\nSubmitting clear, detailed reports is highly encouraged. Each report should explain one vulnerability in detail, identify its impact, and most importantly include steps or a \"proof of concept\" instructions to reproduce the issue.\n\n*Very low-quality reports, such as those which only contain automated output, will be rejected.*\n\n* Let us know as soon as possible upon discovery of a potential security issue, and we'll make every effort to quickly resolve the issue. \n* Provide us a reasonable amount of time to resolve the issue before any disclosure to the public or a third-party. \n* Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of service. \n* Only interact with accounts you own or with explicit permission of the account holder. \n* Include attachments such as screenshots or proof of concept code as necessary. \n* Disclose the vulnerability report directly and exclusively to us.\n\n# Rewards\n\nPlease see our reward table above.\n\nTo qualify for a reward under this program, you should be the first to report the vulnerability.\n\n# Scope\n\nAt this time, the scope of this program is limited to security vulnerabilities found on Chaturbate and its supporting services. Vulnerabilities reported for other properties may be considered on a case-by-case basis.\n\n# Exclusions \nWhile researching, refrain from: \n* Interfering with other users of the site\n* Spamming \n* Social engineering (including phishing) of staff or contractors \n* Any physical attempts against property or data centers \n* Scripting or other automation and brute forcing of intended functionality\n\n### Denial of Service and Brute Force\nTargeted brute force attacks are permitted to discover incorrect or missing rate limits; however the request rate *must* be under **100 requests per minute** for an endpoint. E.g. checking the rate limit on a password input.\nAdditionally the requests must only be made against your own accounts.\n\nA missing rate limit does not always signify a security issue, only endpoints performing sensitive actions may be considered.\n\nIndiscriminate brute forcing or Denial of Service above the specified rate are not permitted.\n\n### The following reports do not qualify\n\n* Reports regarding using the same email for multiple accounts\n* Reports regarding username enumeration\n* Reports about the external_url page \n* Reports about password requirement for changing email\n* Reports against other sites, such as \"stream ripping\" or \"stream capping\" sites\n* Reports that involve manipulating the room user count\n* Reports regarding ability to frame/embed the register and room viewing pages\n* Bugs requiring exceedingly unlikely user interaction\n* HttpOnly and Secure cookie flags\n* Reports of software version disclosure\n* Reporting vulnerabilities that are deemed as accepted risks\n* Bugs that don’t affect the latest version of modern browsers, or browser extensions.\n* Attacks requiring MITM or physical access to a user's device\n* Previously known vulnerable libraries without a working Proof of Concept.\n* Content spoofing and text injection issues without showing an attack vector/without being able to modify HTML/CSS\n\n\n# Safe Harbor \nAny activities conducted in a manner consistent with this policy will be considered authorized conduct and we will not initiate legal action against you. If legal action is initiated by a third party against you in connection with activities conducted under this policy, we will take steps to make it known that your actions were conducted in compliance with this policy. \n\nThank you for helping keep Chaturbate and our users safe!\n","has_open_scope":null,"pays_within_one_month":null,"protected_by_gold_standard_safe_harbor":null,"protected_by_ai_safe_harbor":null,"disclosure_declaration":null,"introduction":null,"platform_standards_exclusions":[],"exemplary_standards_exclusions":[],"scope_exclusions":[],"timestamp":"2018-11-01T05:56:52.153Z"},{"id":3590613,"new_policy":"\n# Security Stance\n\nSecurity and transparency are top priorities at Chaturbate. Networks are dynamic. The technology, users, data in the systems, risks, and security requirements are ever-changing. Chaturbate knows that security is never perfect and can never be taken for granted. People will discover new ways to intentionally or unintentionally bypass or subvert security.  \n\nTime can expose new vulnerabilities, and the most effective way to counteract these vulnerabilities is to become aware of them quickly and to fix them immediately with rewards for you.\n\n# Reporting Guidelines\n\nSubmitting clear, detailed reports is highly encouraged. Each report should explain one vulnerability in detail, identify its impact, and most importantly include steps or a \"proof of concept\" instructions to reproduce the issue.\n\n*Very low-quality reports, such as those which only contain automated output, will be rejected.*\n\n* Let us know as soon as possible upon discovery of a potential security issue, and we'll make every effort to quickly resolve the issue. \n* Provide us a reasonable amount of time to resolve the issue before any disclosure to the public or a third-party. \n* Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of service. \n* Only interact with accounts you own or with explicit permission of the account holder. \n* Include attachments such as screenshots or proof of concept code as necessary. \n* Disclose the vulnerability report directly and exclusively to us.\n\n# Rewards\n\nPlease see our reward table above.\n\nTo qualify for a reward under this program, you should be the first to report the vulnerability.\n\n# Scope\n\nAt this time, the scope of this program is limited to security vulnerabilities found on Chaturbate and its supporting services. Vulnerabilities reported for other properties may be considered on a case-by-case basis.\n\n# Exclusions \nWhile researching, refrain from: \n* Interfering with other users of the site\n* Spamming \n* Social engineering (including phishing) of staff or contractors \n* Any physical attempts against property or data centers \n* Scripting or other automation and brute forcing of intended functionality\n\n### Denial of Service and Brute Force\nTargeted brute force attacks are permitted to discover incorrect or missing rate limits; however the request rate *must* be under **100 requests per minute** for an endpoint. E.g. checking the rate limit on a password input.\nAdditionally the requests must only be made against your own accounts.\n\nIndiscriminate brute forcing or Denial of Service above the specified rate are not permitted.\n\n### The following reports do not qualify\n\n* Reports regarding using the same email for multiple accounts\n* Reports regarding username enumeration\n* Reports about the external_url page \n* Reports about password requirement for changing email\n* Reports against other sites, such as \"stream ripping\" or \"stream capping\" sites\n* Reports that involve manipulating the room user count\n* Reports regarding ability to frame/embed the register and room viewing pages\n* Bugs requiring exceedingly unlikely user interaction\n* HttpOnly and Secure cookie flags\n* Reports of software version disclosure\n* Reporting vulnerabilities that are deemed as accepted risks\n* Bugs that don’t affect the latest version of modern browsers, or browser extensions.\n* Attacks requiring MITM or physical access to a user's device\n* Previously known vulnerable libraries without a working Proof of Concept.\n* Content spoofing and text injection issues without showing an attack vector/without being able to modify HTML/CSS\n\n\n# Safe Harbor \nAny activities conducted in a manner consistent with this policy will be considered authorized conduct and we will not initiate legal action against you. If legal action is initiated by a third party against you in connection with activities conducted under this policy, we will take steps to make it known that your actions were conducted in compliance with this policy. \n\nThank you for helping keep Chaturbate and our users safe!\n","has_open_scope":null,"pays_within_one_month":null,"protected_by_gold_standard_safe_harbor":null,"protected_by_ai_safe_harbor":null,"disclosure_declaration":null,"introduction":null,"platform_standards_exclusions":[],"exemplary_standards_exclusions":[],"scope_exclusions":[],"timestamp":"2018-10-05T01:23:08.892Z"},{"id":3589525,"new_policy":"\n# Security Stance\n\nSecurity and transparency are top priorities at Chaturbate. Networks are dynamic. The technology, users, data in the systems, risks, and security requirements are ever-changing. Chaturbate knows that security is never perfect and can never be taken for granted. People will discover new ways to intentionally or unintentionally bypass or subvert security.  \n\nTime can expose new vulnerabilities, and the most effective way to counteract these vulnerabilities is to become aware of them quickly and to fix them immediately with rewards for you.\n\n# Reporting Guidelines\n\nSubmitting clear, detailed reports is highly encouraged. Each report should explain one vulnerability in detail, identify its impact, and most importantly include steps or a \"proof of concept\" instructions to reproduce the issue.\n\n*Very low-quality reports, such as those which only contain automated output, will be rejected.*\n\n* Let us know as soon as possible upon discovery of a potential security issue, and we'll make every effort to quickly resolve the issue. \n* Provide us a reasonable amount of time to resolve the issue before any disclosure to the public or a third-party. \n* Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of service. \n* Only interact with accounts you own or with explicit permission of the account holder. \n* Include attachments such as screenshots or proof of concept code as necessary. \n* Disclose the vulnerability report directly and exclusively to us.\n\n# Rewards\n\nPlease see our reward table above.\n\nTo qualify for a reward under this program, you should be the first to report the vulnerability.\n\n# Scope\n\nAt this time, the scope of this program is limited to security vulnerabilities found on Chaturbate and its supporting services. Vulnerabilities reported for other properties may be considered on a case-by-case basis.\n\n# Exclusions \nWhile researching, refrain from: \n* Interfering with other users of the site\n* Spamming \n* Social engineering (including phishing) of staff or contractors \n* Any physical attempts against property or data centers \n* Scripting or other automation and brute forcing of intended functionality\n\n### Denial of Service and Brute Force\nTargeted brute force attacks are permitted to discover incorrect or missing rate limits; however the request rate *must* be under **100 requests per minute** for an endpoint. E.g. checking the rate limit on a password input.\nAdditionally the requests must only be made against your own accounts.\n\nIndiscriminate brute forcing or Denial of Service above the specified rate are not permitted.\n\n### The following reports do not qualify\n\n* Reports regarding using the same email for multiple accounts\n* Reports regarding username enumeration\n* Reports about the external_url page \n* Reports about password requirement for changing email\n* Reports against other sites, such as \"stream ripping\" or \"stream capping\" sites\n* Reports that involve manipulating the room user count\n* Reports regarding ability to frame/embed the register and room viewing pages\n* Bugs requiring exceedingly unlikely user interaction\n* HttpOnly and Secure cookie flags\n* Reports of software version disclosure\n* Reporting vulnerabilities that are deemed as accepted risks\n* Bugs that don’t affect the latest version of modern browsers, or browser extensions.\n\n# Safe Harbor \nAny activities conducted in a manner consistent with this policy will be considered authorized conduct and we will not initiate legal action against you. If legal action is initiated by a third party against you in connection with activities conducted under this policy, we will take steps to make it known that your actions were conducted in compliance with this policy. \n\nThank you for helping keep Chaturbate and our users safe!\n","has_open_scope":null,"pays_within_one_month":null,"protected_by_gold_standard_safe_harbor":null,"protected_by_ai_safe_harbor":null,"disclosure_declaration":null,"introduction":null,"platform_standards_exclusions":[],"exemplary_standards_exclusions":[],"scope_exclusions":[],"timestamp":"2018-09-22T22:23:06.134Z"},{"id":3589475,"new_policy":"\n# Security Stance\n\nSecurity and transparency are top priorities at Chaturbate. Networks are dynamic. The technology, users, data in the systems, risks, and security requirements are ever-changing. Chaturbate knows that security is never perfect and can never be taken for granted. People will discover new ways to intentionally or unintentionally bypass or subvert security.  \n\nTime can expose new vulnerabilities, and the most effective way to counteract these vulnerabilities is to become aware of them quickly and to fix them immediately with rewards for you.\n\n# Reporting Guidelines\n\nSubmitting clear, detailed reports is highly encouraged. Each report should explain one vulnerability in detail, identify its impact, and most importantly include steps or a \"proof of concept\" instructions to reproduce the issue.\n\n*Very low-quality reports, such as those which only contain automated output, will be rejected.*\n\n* Let us know as soon as possible upon discovery of a potential security issue, and we'll make every effort to quickly resolve the issue. \n* Provide us a reasonable amount of time to resolve the issue before any disclosure to the public or a third-party. \n* Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of service. \n* Only interact with accounts you own or with explicit permission of the account holder. \n* Include attachments such as screenshots or proof of concept code as necessary. \n* Disclose the vulnerability report directly and exclusively to us.\n\n# Rewards\n\nPlease see our reward table above.\n\nTo qualify for a reward under this program, you should be the first to report the vulnerability.\n\n# Scope\n\nAt this time, the scope of this program is limited to security vulnerabilities found on Chaturbate and its supporting services. Vulnerabilities reported for other properties may be considered on a case-by-case basis.\n\n# Exclusions \nWhile researching, refrain from: \n* Interfering with other users of the site\n* Spamming \n* Social engineering (including phishing) of staff or contractors \n* Any physical attempts against property or data centers \n* Scripting or other automation and brute forcing of intended functionality\n* Reports about the external_url page \n* Reports about password requirement for changing email\n\n### Denial of Service and Brute Force\nTargeted brute force attacks are permitted to discover incorrect or missing rate limits; however the request rate *must* be under **100 requests per minute** for an endpoint. E.g. checking the rate limit on a password input.\nAdditionally the requests must only be made against your own accounts.\n\nIndiscriminate brute forcing or Denial of Service above the specified rate are not permitted.\n\n### The following reports do not qualify\n\n* Reports regarding using the same email for multiple accounts\n* Reports regarding username enumeration\n* Reports against other sites, such as \"stream ripping\" or \"stream capping\" sites\n* Reports that involve manipulating the room user count\n* Reports regarding ability to frame/embed the register and room viewing pages\n* Bugs requiring exceedingly unlikely user interaction\n* HttpOnly and Secure cookie flags\n* Reports of software version disclosure\n* Reporting vulnerabilities that are deemed as accepted risks\n* Bugs that don’t affect the latest version of modern browsers, or browser extensions.\n\n# Safe Harbor \nAny activities conducted in a manner consistent with this policy will be considered authorized conduct and we will not initiate legal action against you. If legal action is initiated by a third party against you in connection with activities conducted under this policy, we will take steps to make it known that your actions were conducted in compliance with this policy. \n\nThank you for helping keep Chaturbate and our users safe!\n","has_open_scope":null,"pays_within_one_month":null,"protected_by_gold_standard_safe_harbor":null,"protected_by_ai_safe_harbor":null,"disclosure_declaration":null,"introduction":null,"platform_standards_exclusions":[],"exemplary_standards_exclusions":[],"scope_exclusions":[],"timestamp":"2018-09-21T23:22:49.749Z"},{"id":3589394,"new_policy":"\n# Security Stance\n\nSecurity and transparency are top priorities at Chaturbate. Networks are dynamic. The technology, users, data in the systems, risks, and security requirements are ever-changing. Chaturbate knows that security is never perfect and can never be taken for granted. People will discover new ways to intentionally or unintentionally bypass or subvert security.  \n\nTime can expose new vulnerabilities, and the most effective way to counteract these vulnerabilities is to become aware of them quickly and to fix them immediately with rewards for you.\n\n# Reporting Guidelines\n\nSubmitting clear, detailed reports is highly encouraged. Each report should explain one vulnerability in detail, identify its impact, and most importantly include steps or a \"proof of concept\" instructions to reproduce the issue.\n\n*Very low-quality reports, such as those which only contain automated output, will be rejected.*\n\n* Let us know as soon as possible upon discovery of a potential security issue, and we'll make every effort to quickly resolve the issue. \n* Provide us a reasonable amount of time to resolve the issue before any disclosure to the public or a third-party. \n* Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of service. \n* Only interact with accounts you own or with explicit permission of the account holder. \n* Include attachments such as screenshots or proof of concept code as necessary. \n* Disclose the vulnerability report directly and exclusively to us.\n\n# Rewards\n\nPlease see our reward table above.\n\nTo qualify for a reward under this program, you should be the first to report the vulnerability.\n\n# Scope\n\nAt this time, the scope of this program is limited to security vulnerabilities found on Chaturbate and its supporting services. Vulnerabilities reported for other properties may be considered on a case-by-case basis.\n\n# Exclusions \nWhile researching, refrain from: \n* Interfering with other users of the site\n* Spamming \n* Social engineering (including phishing) of staff or contractors \n* Any physical attempts against property or data centers \n* Scripting or other automation and brute forcing of intended functionality\n\n### Denial of Service and Brute Force\nTargeted brute force attacks are permitted to discover incorrect or missing rate limits; however the request rate *must* be under **100 requests per minute** for an endpoint. E.g. checking the rate limit on a password input.\nAdditionally the requests must only be made against your own accounts.\n\nIndiscriminate brute forcing or Denial of Service above the specified rate are not permitted.\n\n### The following reports do not qualify\n\n* Reports regarding using the same email for multiple accounts\n* Reports regarding username enumeration\n* Reports against other sites, such as \"stream ripping\" or \"stream capping\" sites\n* Reports that involve manipulating the room user count\n* Reports regarding ability to frame/embed the register and room viewing pages\n* Bugs requiring exceedingly unlikely user interaction\n* HttpOnly and Secure cookie flags\n* Reports of software version disclosure\n* Reporting vulnerabilities that are deemed as accepted risks\n* Bugs that don’t affect the latest version of modern browsers, or browser extensions.\n\n# Safe Harbor \nAny activities conducted in a manner consistent with this policy will be considered authorized conduct and we will not initiate legal action against you. If legal action is initiated by a third party against you in connection with activities conducted under this policy, we will take steps to make it known that your actions were conducted in compliance with this policy. \n\nThank you for helping keep Chaturbate and our users safe!\n","has_open_scope":null,"pays_within_one_month":null,"protected_by_gold_standard_safe_harbor":null,"protected_by_ai_safe_harbor":null,"disclosure_declaration":null,"introduction":null,"platform_standards_exclusions":[],"exemplary_standards_exclusions":[],"scope_exclusions":[],"timestamp":"2018-09-21T02:11:25.172Z"},{"id":3589384,"new_policy":"\n# Security Stance\n\nSecurity and transparency are top priorities at Chaturbate. Networks are dynamic. The technology, users, data in the systems, risks, and security requirements are ever-changing. Chaturbate knows that security is never perfect and can never be taken for granted. People will discover new ways to intentionally or unintentionally bypass or subvert security.  \n\nTime can expose new vulnerabilities, and the most effective way to counteract these vulnerabilities is to become aware of them quickly and to fix them immediately with rewards for you.\n\n# Reporting Guidelines\n\nSubmitting clear, detailed reports is highly encouraged. Each report should explain one vulnerability in detail, identify its impact, and most importantly include steps or a \"proof of concept\" instructions to reproduce the issue.\n\n*Very low-quality reports, such as those which only contain automated output, will be rejected.*\n\n* Let us know as soon as possible upon discovery of a potential security issue, and we'll make every effort to quickly resolve the issue. \n* Provide us a reasonable amount of time to resolve the issue before any disclosure to the public or a third-party. \n* Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of service. \n* Only interact with accounts you own or with explicit permission of the account holder. \n* Include attachments such as screenshots or proof of concept code as necessary. \n* Disclose the vulnerability report directly and exclusively to us.\n\n# Rewards\n\nPlease see our reward table above.\n\nTo qualify for a reward under this program, you should be the first to report the vulnerability.\n\n# Scope\n\nAt this time, the scope of this program is limited to security vulnerabilities found on Chaturbate and its supporting services. Vulnerabilities reported for other properties may be considered on a case-by-case basis.\n\n# Exclusions \nWhile researching, refrain from: \n* Interfering with other users of the site\n* Spamming \n* Social engineering (including phishing) of staff or contractors \n* Any physical attempts against property or data centers \n* Scripting or other automation and brute forcing of intended functionality\n\n### Denial of Service and Brute Force\nTargeted brute force attacks are permitted to discover incorrect or missing rate limits; however the request rate *must* be under **100 requests per minute** for an endpoint. E.g. checking the rate limit on a password input.\nAdditionally the requests must only be made against your own accounts.\n\nIndiscriminate brute forcing or Denial of Service above the specified rate are not permitted.\n\n### The following reports do not qualify\n\n* Reports regarding using the same email for multiple accounts\n* Reports regarding username enumeration\n* Reports against other sites, such as \"stream ripping\" or \"stream capping\" sites\n* Reports that involve manipulating the room user count\n* Bugs requiring exceedingly unlikely user interaction\n* HttpOnly and Secure cookie flags\n* Reports of software version disclosure\n* Reporting vulnerabilities that are deemed as accepted risks\n* Bugs that don’t affect the latest version of modern browsers, or browser extensions.\n\n# Safe Harbor \nAny activities conducted in a manner consistent with this policy will be considered authorized conduct and we will not initiate legal action against you. If legal action is initiated by a third party against you in connection with activities conducted under this policy, we will take steps to make it known that your actions were conducted in compliance with this policy. \n\nThank you for helping keep Chaturbate and our users safe!\n","has_open_scope":null,"pays_within_one_month":null,"protected_by_gold_standard_safe_harbor":null,"protected_by_ai_safe_harbor":null,"disclosure_declaration":null,"introduction":null,"platform_standards_exclusions":[],"exemplary_standards_exclusions":[],"scope_exclusions":[],"timestamp":"2018-09-20T22:45:07.879Z"},{"id":3589089,"new_policy":"\n# Security Stance\n\nSecurity and transparency are top priorities at Chaturbate. Networks are dynamic. The technology, users, data in the systems, risks, and security requirements are ever-changing. Chaturbate knows that security is never perfect and can never be taken for granted. People will discover new ways to intentionally or unintentionally bypass or subvert security.  \n\nTime can expose new vulnerabilities, and the most effective way to counteract these vulnerabilities is to become aware of them quickly and to fix them immediately with rewards for you.\n\n# Reporting Guidelines\n\nSubmitting clear, detailed reports is highly encouraged. Each report should explain one vulnerability in detail, identify its impact, and most importantly include steps or a \"proof of concept\" instructions to reproduce the issue.\n\n*Very low-quality reports, such as those which only contain automated output, will be rejected.*\n\n* Let us know as soon as possible upon discovery of a potential security issue, and we'll make every effort to quickly resolve the issue. \n* Provide us a reasonable amount of time to resolve the issue before any disclosure to the public or a third-party. \n* Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of service. \n* Only interact with accounts you own or with explicit permission of the account holder. \n* Include attachments such as screenshots or proof of concept code as necessary. \n* Disclose the vulnerability report directly and exclusively to us.\n\n# Rewards\n\nPlease see our reward table above.\n\nTo qualify for a reward under this program, you should be the first to report the vulnerability.\n\n# Scope\n\nAt this time, the scope of this program is limited to security vulnerabilities found on Chaturbate and its supporting services. Vulnerabilities reported for other properties may be considered on a case-by-case basis.\n\n# Exclusions \nWhile researching, refrain from: \n* Interfering with other users of the site\n* Spamming \n* Social engineering (including phishing) of staff or contractors \n* Any physical attempts against property or data centers \n* Scripting or other automation and brute forcing of intended functionality\n\n### Denial of Service and Brute Force\nTargeted brute force attacks are permitted to discover incorrect or missing rate limits; however the request rate *must* be under **100 requests per minute** for an endpoint. E.g. checking the rate limit on a password input.\nAdditionally the requests must only be made against your own accounts.\n\nIndiscriminate brute forcing or Denial of Service above the specified rate are not permitted.\n\n### The following reports do not qualify\n\n* Reports against other sites, such as \"stream ripping\" or \"stream capping\" sites\n* Reports that involve manipulating the room user count\n* Bugs requiring exceedingly unlikely user interaction\n* HttpOnly and Secure cookie flags\n* Reports of software version disclosure\n* Reporting vulnerabilities that are deemed as accepted risks\n* Bugs that don’t affect the latest version of modern browsers, or browser extensions.\n\n# Safe Harbor \nAny activities conducted in a manner consistent with this policy will be considered authorized conduct and we will not initiate legal action against you. If legal action is initiated by a third party against you in connection with activities conducted under this policy, we will take steps to make it known that your actions were conducted in compliance with this policy. \n\nThank you for helping keep Chaturbate and our users safe!\n","has_open_scope":null,"pays_within_one_month":null,"protected_by_gold_standard_safe_harbor":null,"protected_by_ai_safe_harbor":null,"disclosure_declaration":null,"introduction":null,"platform_standards_exclusions":[],"exemplary_standards_exclusions":[],"scope_exclusions":[],"timestamp":"2018-09-19T01:16:09.679Z"}]