Reporting a security issue.
Write to security@macupp.com. One person reads it, and you will get a reply from someone who can actually fix the thing rather than an acknowledgement that a ticket exists.
Machine readable version at /.well-known/security.txt
How it is built
What is protected, and how
Bucketree holds credentials for your Backblaze account, so these are the claims worth checking rather than taking on trust.
Keys stay on your Mac
They are written to the macOS data protection keychain and sent to Backblaze. There is no account with us, and therefore nowhere for them to be sent.
Credentials stay out of the log
The Activity Log is safe to send us with a bug report: the account key, the authorization token and the token inside a share link are all kept out of it, and a test enforces that.
Signed and notarized
An Apple Developer ID signature, Apple notarization, and the App Sandbox. The application can reach your keychain items, the folder you chose, and Backblaze.
If you find any of that to be untrue, that is exactly the report we want.
What we ask, and what we promise
What to send
Enough for us to reproduce it. The version and build from Bucketree then About Bucketree, your macOS version, and the steps. If it involves a bucket or a key, describe the configuration rather than sending us credentials. We will never ask you for a key.
What we will do
Acknowledge within three working days, tell you honestly whether we think it is a vulnerability, and keep you informed while it is being fixed. If you want credit when it is published, say so and you will get it. If you would rather stay anonymous, that is fine too.
What we offer is credit and a straight answer, rather than a paid bug bounty.
Safe harbour
If you make a good faith effort to follow this page, we will not pursue or support legal action against you for your research, and we will say so publicly if anyone else tries to. Good faith means you did not access, modify or delete data belonging to anyone else, did not degrade the service for other people, and gave us a reasonable chance to fix the problem before telling the world.
In scope
The Bucketree application, this website, and the update mechanism that delivers new versions to the application.
Where to send the rest
Backblaze B2 itself. If you have found something in B2, Backblaze want to hear from you and we are not a useful intermediary. The same goes for Freemius, who process payments, and for Apple.
We also set aside reports produced entirely by an automated scanner with no evidence of impact, missing headers with no demonstrated consequence, and anything needing physical access to an unlocked Mac that is already signed in.