Security
Security controls have limits. Commonside is an early-stage service, not an anonymity or end-to-end encryption product.
Current controls
- HTTPS for websites, TLS for IMAP and SMTP submission, and certificate verification for Roundcube's mail connections.
- Password hashing, hashed registration tokens, single-use registration links with 5-day expiry, and password plus TOTP for staff authentication.
- Session cookies, form checks, input validation and rate limiting on sensitive application routes.
- Separate application/admin/mail databases, restricted service identities and audit records for sensitive actions.
- Server-side mailbox message encryption with server-held keys. It does not prevent privileged operator access.
- MTA-STS policy for incoming mail at mx1.commonside.org. Sender support varies; this does not encrypt message content end to end.
Protect your account
Use a unique password and keep your recovery code separately. Confirmed accounts require the saved code for password changes and the previous code for rotation. Older accounts whose code was not confirmed can establish one using their current password. Lost-password recovery consumes its code. Revoke other panel sessions from the security page when needed; mail-client sessions are separate.
Known limitations
Username changes are temporarily disabled. Complete off-host mailbox/key restore protection and one-click staff webmail login are not yet available. Keep independent backups of important messages.
Report a concern
Contact support@commonside.org. Label security reports clearly and give a minimal description first so volunteers can arrange safe handling of sensitive evidence. Do not publish secrets, access other users' data or disrupt service.
