Security

If you have found a vulnerability in Outstation, in the outstationd agent, or in the relay, tell us at security@quirl.co.

Include enough to reproduce it. A proof of concept is welcome and never required — a clear description of the flaw is worth more than a half-working exploit. If it is easier to talk than to write, say so and we will find a way.

The machine-readable version of this page is at /.well-known/security.txt.

what to expect

Will a person read it?
Yes. Outstation is a one-person project, so there is no triage queue and no auto-responder — the target is a human reply within five working days. If a week goes by with nothing, assume the mail went astray rather than that it was ignored, and send it again.
Is there a bounty?
No, and we would rather say so plainly than let you find out after the work. Credit in the release notes if you want it, and silence if you would prefer that.
Can I publish?
Yes. We ask for a chance to ship a fix first, and we will tell you honestly how long that will take rather than asking for an open-ended delay. Nothing here asks you to sign anything.
Am I going to be sued?
Not for good-faith research within the scope below. We will not pursue or support legal action over testing that stays inside it, stops at the first sign of a real user's data, and reports what it finds. That promise is ours to make and does not bind Fly, Vercel or Apple, whose own terms still apply to you.

in scope

  • relay.outstation.dev — the relay that Outstation Connect splices sessions through.
  • outstationd — the agent that runs on a user's Mac, holds a private key and dials out.
  • The Outstation iPad app, including how it stores keys and how it pins host keys.
  • outstation.dev itself, including the waitlist endpoint.

Test against your own machine and your own link. If a finding needs a second party to demonstrate, describe it and we will stand up a test link rather than have you use someone else's.

not in scope

  • Denial of service, traffic floods, and anything whose demonstration is the harm.
  • Social engineering, phishing, or physical access to anyone's hardware.
  • Findings in Fly, Vercel or Apple themselves — report those to them; we will happily help you work out which.
  • Reports produced by running a scanner and forwarding its output. A missing header on a static page with no cookies and no logins is not a vulnerability, and we will say so.

What the relay can and cannot see

Worth stating precisely, because it decides which reports matter and because it is the honest answer to most of them.

Your session is end-to-end encrypted, and the encryption is SSH's. The relay adds no cryptography of its own — it moves bytes between two TLS connections it terminates nothing inside. SSH runs between the iPad and your sshd, and nobody in between terminates it. Your machine's host key is pinned when you pair, before the first connection, so the relay cannot impersonate it either.

What the relay does see is metadata: that a link is connected, from which address, for how long, and how many bytes. Never contents. Link identifiers are truncated in logs, because a full one is a credential.

What we do not claim: that this is zero-knowledge, that metadata is hidden, or that a second cryptographic layer exists. It does not. If a report turns on one of those, we would still like to read it — it means this paragraph is not clear enough.

reaching us otherwise

security@quirl.co reaches a person for vulnerabilities, abuse of the relay, and copyright notices alike. One address for all three on purpose — splitting them would only be three chances to pick wrong.

It is on quirl.co because Quirl L.L.C. is the entity behind Outstation, and the name on the installer's Developer ID signature. If you have just checked that signature, this is the same name.

For anything that is not a security matter — installing the agent, getting a link added — outstation@quirl.co is the better door.

This page is the policy referenced by security.txt. It changes when the product does; the Expires field there is a commitment to keep it current rather than a formality.

back to the session

Copyright, abuse, and repeat infringers

Outstation Connect is a conduit. It transmits material at a user's direction, chooses none of it, modifies none of it, and stores no copy beyond what a byte in flight requires.

Send notices to security@quirl.co with enough detail to identify the material and the link, your contact details, and a statement that you believe in good faith that the use is not authorised.

What we can do about it is narrow, and worth being straight about. We cannot take down content we have never had a copy of and cannot read. What we can do — and will — is terminate a link. That is a real control and not a promise about one: revoking closes the sockets already open as well as refusing the next connection, so it takes effect immediately rather than whenever someone happens to disconnect.

Repeat infringers lose their access. Where a user is the subject of repeated substantiated notices, their link is terminated and not reissued. This is the policy referred to in 17 U.S.C. §512(i), and publishing it here is how users are informed of it.

We will also terminate a link for using the relay to attack other systems, or to reach anything other than the machine it was paired to — the agent only ever connects to 127.0.0.1, so the second is a bug report as much as an abuse report, and we would want to hear it either way.

counter-notice

If your link was terminated over a notice you believe is mistaken, reply to the message you were sent. Say who you are, what was terminated, and why you believe the notice was wrong.

Notices sent in bad faith carry their own consequences under §512(f). We read them as coming from a person who believes what they are saying, and we expect the same of you.

outstation