Ophio / Security

Keep the roots
private.

Private vulnerability reporting opens on GitHub with the public release. Until then, don’t publish exploit details anywhere.

What to include

Include affected version/platform, required access, expected and observed behaviour, and a minimal synthetic reproduction. Remove device keys, pairing offers, account tokens, screenshots, typed text and personal paths.

If a device is exposed

Revoke its pairing on the computer. If you can’t tell who still has access, stop Ophio. Never accept an unfamiliar certificate just to get connected again.

Everything else

GitHub Issues opens for help with the public release.