Found a vulnerability? Email [email protected]. We acknowledge within 48 hours. No legal action against good-faith security researchers.