Security
Report a security problem
If you think you’ve found a weakness in Matchbox, in the display on the wall, the app, our service or this website, please tell us. We’ll take it seriously and work with you to fix it.
How to report it
Email malik@staytethered.app with “Security” in the subject. You don’t need to give us your name or any other personal details: an address we can reply to is enough, and you can ask us not to keep it once we’re done.
It helps to include:
- which part of Matchbox it affects, and the version if you know it;
- what you found, and the steps that show it;
- what you think someone could do with it;
- whether you’d like to be credited when it’s fixed, and under what name.
What happens next
- We’ll confirm we’ve received your report.
- We’ll tell you what we found and what we’re doing about it, and keep you updated until it’s resolved.
- When it’s fixed, we’ll tell you, and agree with you when it’s safe to talk about it publicly. We’re happy to credit you.
Fixes reach a Matchbox on their own, over Wi-Fi, and the app updates through the app stores.
Testing in good faith
Please:
- test only against your own Matchbox and your own account;
- don’t access, change or delete anyone else’s data, and stop if you come across any;
- don’t disrupt the service for other people, and don’t send spam or test by deceiving anyone;
- give us a reasonable time to fix a problem before you share it with anyone else.
Problems in the services Matchbox relies on, such as Amazon Web Services, Apple, Google or our sports data provider, belong with those companies. Tell us too if it affects Matchbox.
For machines
The same contact is published at /.well-known/security.txt, as described in RFC 9116.