Skip to content

Security: valinux/nuclear-messenger

SECURITY.md

Security and responsible operation

This is experimental numbers-station research/education software. It is not a certified emergency system. Users are responsible for their hardware, software modifications, transmitted content and applicable operating rules. See LICENSES.md and the license texts for warranty/liability terms.

Trust boundaries

  • Traffic is unencrypted; station IDs are not authenticated. CRC and SHA-256 detect damaged/inconsistent transfers, not a malicious authenticated peer.
  • Received files can contain hostile data. The station saves them and does not execute or open them automatically. Inspect them before opening elsewhere.
  • The Flask panel is intended for localhost on the station computer. Its session token, host/origin checks and CSP are not a public multi-user service. Do not expose its control port to the internet or remove these checks casually.
  • Runtime data contains plaintext messages/files and device settings. Keep it out of repositories and screenshots. Back it up and protect access yourself.
  • A dictionary substitution is not encryption. Do not claim it supplies secrecy, authentication, one-time-pad security or resistance to analysis.
  • Hardware PTT, volume and microphone controls remain outside the software. A stopped player cannot recall transmitted audio or release a manual PTT.

Reporting a vulnerability

Use the repository's Security → Report a vulnerability private reporting form: private report. Include the affected commit, OS/dependencies, minimal reproduction and impact. Avoid sending private recordings, credentials, real station traffic or unnecessary exploit payloads. If private reporting is unavailable, open an issue requesting a private contact channel without disclosing the vulnerability. No response time or security support period is guaranteed.

For ordinary decoder/audio problems, use a normal bug report with fictional reproduction data and make clear whether it used physical hardware or a WAV.

There aren't any published security advisories