RocketChat is no longer a suitable tool for use in organizations

That is an automailer that will just answer the following:

Thank you for reaching out to Rocket.Chat. We will respond to your email as soon as possible.

If your email is about reporting a security vulnerability, we kindly ask you to directly submit the report into our Hackerone program here: HackerOne
Once you have submitted there, we will follow up directly in Hackerone.

Regards
The Rocket.Chat Security Team

I’m starting to believe they haven’t had a security team for the last two years.

1 Like

Yeah it looks that way, but it isn’t actually quite true I can assure you. No, it probably hasn’t been ‘good enough’ though.

I have raised the issue of HackOne with the powers that be and I think you will find it is open again.

I did mention the fact that if you want to proclaim to be secure then it starts with your own security :wink:

Let see what comes of it.