Reporting bugs

We take security very seriously. Thank you for taking the time to responsibly disclose any issues you find.

All security bugs in Gasolina Móvil should be reported by email to [email protected]. This list is delivered to a subset of the team who handle security issues. Your email will be acknowledged within 24 hours, and you'll receive a more detailed response to your email within 48 hours indicating the next steps in handling your report. You can encrypt your email using our public key.

This email address receives a large amount of spam, so be sure to use a descriptive subject line to avoid having your report be missed. After the initial reply to your report, the security team will endeavor to keep you informed of the progress being made towards a fix and full announcement. These updates will be sent at least every five days. In reality, this is more likely to be every 24-48 hours.

If you have not received a reply to your email within 48 hours, or have not heard from the security team for the past five days, there are a few steps you can take:

  1. Contact the current security coordinator (Giovanni Collazo) directly.
  2. Contact the back-up contact (José Padilla) directly.
  3. Send a DM on twitter to @blimp.

If you have any suggestions to improve this policy, please send an email to [email protected].