Security Policy
1. Our Security Commitment
At myuid.lol, the security of our users, profiles, and platform infrastructure is our highest priority. We follow modern defensive development standards and security best practices to protect user data from unauthorized access and cyber threats.
2. Authentication & Password Storage
Passwords are never stored in plain text or using outdated hashing functions. We utilize industry-standard cryptographic hashing functions (Bcrypt/Argon2ID with automatic salting). Account enumeration is mitigated through normalized timing responses.
3. Session Management & Cookies
All platform communication is enforced through HTTPS encryption. Session cookies are marked with strict HttpOnly, Secure, and SameSite=Lax attributes. Sessions are subject to automatic periodic ID regeneration and idle timeout expiration.
4. Database & Input Sanitation
To prevent SQL injection, all database queries execute strictly through native PDO prepared statements with parameter binding. User-supplied HTML is thoroughly sanitized and escaped to eliminate Cross-Site Scripting (XSS) risks.
5. Upload Hardening & File Execution Defense
All uploaded avatars and banner images are re-encoded through graphics processors to strip EXIF data and polyglot payloads. The media uploads directory has script execution entirely disabled at the web server level.
6. Responsible Vulnerability Disclosure
We welcome reports from independent security researchers. If you believe you have found a vulnerability in our application or infrastructure, we ask that you practice responsible disclosure:
- Submit your detailed findings through our Contact Page with the category "Security / Vulnerability".
- Give our engineering team reasonable time to investigate and remediate the issue before public disclosure.
- Do not access, download, or modify user accounts, private data, or disrupt service availability during your testing.
7. Security Contact
For urgent security disclosures, please submit an inquiry via our Contact Page. We take all legitimate reports seriously and respond promptly.