Skip to content

Security: sgInnora/hash-collision-lab

Security

SECURITY.md

Security Policy

About This Repository

This is an academic security research repository published by Innora AI Security Research Lab. All proof-of-concept demonstrations in this repository have been fully redacted — private keys, server addresses, production credentials, and other sensitive data have been removed or replaced with placeholders before public release.

For the full responsible disclosure timeline, see RESPONSIBLE-DISCLOSURE.md.

Supported Versions

This repository contains historical research artifacts and is not a maintained software product. No version support matrix applies.

Reporting a Vulnerability

If you identify a security issue within this repository itself (e.g., accidentally committed sensitive data, a supply-chain risk in tooling, etc.), please report it responsibly:

  • Email: feng@innora.ai
  • Subject: [SECURITY] hash-collision-lab — <brief description>
  • Response time: We aim to respond within 72 hours.

Please do not open a public GitHub issue for security-sensitive findings.

Scope

In Scope Out of Scope
Sensitive data accidentally present in this repo Vulnerabilities in third-party tools referenced by the research
Security issues in the repository's CI/tooling Theoretical weaknesses already documented in the paper

Research Ethics

All vulnerabilities described in this repository were reported to the affected vendor (Ant Group) before public disclosure, following the 90-day coordinated disclosure standard. See RESPONSIBLE-DISCLOSURE.md for the full timeline.

Contact

There aren’t any published security advisories