DUE TO SPAM, SIGN-UP IS DISABLED. Goto Selfserve wiki signup and request an account.
...
- Are logs intended to be safe to expose to users with read-only authorization, or may they contain credentials?
- If your project has a web interface, are users who have an account with 'admin' authorization on the web interface also trusted to trigger arbitrary OS commands?
- Is it a problem when an unauthenticated user can easily determine the deployed version?
- Is it OK if an attacker can discover what usernames are valid for the system?
For particularly tricky edge cases, you could explicitly state that while you don't guarantee a certain type of safety, you do strive for it, and will still welcome reports about such cases since you intend to fix those as security hardening improvements.