Security
Found a security problem in QuestPump? Please tell us privately first, so we can fix it before anyone misuses it.
This policy covers QuestPump by Pluxia GmbH, a Swiss company: the QuestPump add-on for World of Warcraft, QuestPump Helper for Mac and Windows, the QuestPump apps for iPhone, Apple Watch, Android and Wear OS, and this website. The game itself and other companies' services are out of scope.
Where to write
Please report it privately, never in a public issue:
- by email to security@questpump.com, or
- for the helper, whose code is public, through GitHub's private vulnerability reporting:github.com/Pluxia-GmbH/questpump.
What to include
- What is affected: the add-on, the helper, an app or the website, with its version and your system.
- What someone could do with the problem, and what they would need to do it.
- The steps to reproduce it, or a proof of concept.
- How we can reach you, and whether you want to be named when the fix ships.
Please test only on your own devices and accounts, send no one's personal or health data, and keep the problem private until a fix is out.
What you can expect
- We aim to confirm your report within 5 working days.
- For a confirmed problem we aim to ship a fix, or to tell you our plan, within 30 days.
- We keep you informed while we work on it and agree a publication date with you. If you wish, we thank you by name in the release notes.
Supported versions
- The helper: only the newest version gets security fixes, and the helper updates itself. Pluxia GmbH supports the helper with security updates for at least five years after its first public release, and at least until 4 November 2031.
- The add-on and the apps: the newest version in their stores.
How the helper's releases are protected
- Signed updates. The helper installs an update only after it has checked the update's minisign signature against the public key built into it. The signature also covers the version number, so an old release cannot pass as a new one.
- Mac: the helper is signed with Pluxia GmbH's Developer ID and notarised by Apple.
- Windows: the helper and its installer are signed in the name of Pluxia GmbH through Microsoft's Artifact Signing.
- A CycloneDX SBOM with every release, one for each build, listing every component in it.
- cargo-deny on every change checks the helper's dependencies for known vulnerabilities (RustSec advisories), yanked versions, licences and sources.
- Releases are built by GitHub Actions from the tagged commit, from a clean build cache.
What the helper exposes
- The LAN API on TCP port 8787 on every address of the computer (IPv4 and IPv6), for the paired phone and watch. Every request carries a token and every body is sealed (AES-256-GCM), both with keys derived (HKDF-SHA256) from the pairing key. The pairing key travels only in the QR code on the computer's screen, never over the network. The one route without the token,
GET /v1/hello, answers with the helper install's random id, an 8-byte one-way id of the pairing key (HKDF-SHA256 again) and the computer's names, so a phone finds its own helper after the address changed before it sends its token anywhere. The helper refuses connections from addresses outside the private network ranges, and on Windows its firewall rule lets in only the local subnet; every refusal is logged, at most once a minute per address. "New pairing code" in the helper's window ends every pairing. - A Bonjour record, on Windows only:
_questpump._tcpwith the computer's name, its address, port 8787, the install's id and the pairing key's id, registered through Windows' own DNS Client, which answers for it; the helper opens no socket for it. On a Mac the helper advertises nothing. - The local socket for tools on the same computer:
helper.sockin the helper's data folder on a Mac, the named pipe\\.\pipe\questpump-helperon Windows, which only the player's own account (and the system) may open. It accepts no connections from other computers. - Bluetooth, only after the player turns on a heart-rate strap in the helper's window.
- Outgoing connections: none except the updater's HTTPS requests to GitHub, where the releases live. The helper sends no telemetry, no crash reports and no analytics, and it has no account.
The helper never runs as an administrator. On Windows two one-time steps, the firewall rule and the right to write into the game folder, each run one command as an administrator after the player accepts the Windows prompt, and uninstalling removes that firewall rule after one more prompt. Updates never ask for an administrator: where the player's Mac account cannot replace the helper's app, the helper says to download the new version instead.
Problems that are being exploited
If a problem in QuestPump is being actively exploited, Pluxia GmbH reports it to the EU's single reporting platform, as the EU Cyber Resilience Act asks (Article 14), and tells the people who use QuestPump what to do.
For tools: security.txt.