Skip to content

Security: Dev4YM/ur2NULL

Security

SECURITY.md

Security Policy

⚠️ Educational Purpose Disclaimer

uR2NULL is an educational project designed to demonstrate browser fingerprinting techniques. This project:

  • Does NOT store or persist any collected data
  • Does NOT track users across sessions
  • Does NOT share data with third parties
  • Is intended SOLELY for educational and research purposes

Supported Versions

Version Supported
1.x

Reporting a Vulnerability

We take security seriously, even for educational projects. If you discover a security vulnerability, please follow responsible disclosure:

What to Report

  • Security vulnerabilities in the code
  • Privacy leaks beyond intended demonstration
  • Data persistence issues (we should never store data)
  • Malicious use potential that wasn't considered

How to Report

  1. DO NOT open a public GitHub issue for security vulnerabilities
  2. Email the maintainer directly (check GitHub profile for contact)
  3. Include:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Suggested fix (if any)

What to Expect

  • Acknowledgment within 48 hours
  • Assessment within 7 days
  • Fix timeline communicated based on severity
  • Credit in the security advisory (if desired)

Security Measures

Data Handling

  • No persistence: All data is ephemeral and exists only in memory
  • No cookies: No tracking cookies are set
  • No cross-session correlation: Each visit is independent
  • No third-party sharing: Data never leaves the demo environment

Server Security

  • CORS restrictions: Only allowed origins can access the API
  • Rate limiting: Prevents abuse of the inference endpoint
  • Input validation: All signals are validated and sanitized
  • No code execution: User input is never executed as code

Client Security

  • No forced permissions: Never requests camera, microphone, or location
  • No exploits: Uses only legitimate browser APIs
  • Transparent collection: All collection is visible in source code
  • No obfuscation: Code is readable and auditable

Ethical Use Policy

Acceptable Use

Educational purposes - Learning about browser fingerprinting
Research - Privacy research and analysis
Awareness - Demonstrating privacy implications
Testing - Testing privacy protection tools

Prohibited Use

Tracking users without consent
Data collection for commercial purposes
Malicious fingerprinting for fraud or exploitation
Circumventing privacy protections maliciously
Any illegal activity

Privacy Considerations

What This Project Collects

This project demonstrates collection of:

  • Hardware information (CPU, GPU, RAM, screen)
  • Browser information (user agent, features, capabilities)
  • Network information (connection type, timing)
  • Environmental information (timezone, locale, theme)

What This Project Does NOT Collect

  • Personal identifiable information (PII)
  • Browsing history
  • Cookies or storage data
  • Keyboard/mouse input
  • Camera or microphone data
  • Location (beyond IP geolocation)

Responsible Disclosure

If you use this project for research that reveals new privacy concerns:

  1. Document your findings thoroughly
  2. Notify browser vendors if applicable
  3. Share with the community responsibly
  4. Consider the impact on user privacy
  5. Propose mitigations where possible

Legal Compliance

GDPR Compliance

This demonstration project:

  • Processes data transiently (no storage)
  • Does not identify individuals
  • Provides transparency about collection
  • Does not require consent for educational demonstration

CCPA Compliance

  • No personal information is sold
  • No data is retained
  • Users can see all collected data
  • No cross-site tracking

Updates

This security policy may be updated as the project evolves. Check back regularly for changes.

Contact

For security concerns: Open an issue with the security label or contact maintainers directly.


Remember: This project exists to educate about privacy risks. Use it responsibly and ethically.

There aren’t any published security advisories