CRY · Security
CRY runs with Administrator and rewrites parts of Windows. This page covers what the app does to limit risk, how to report a flaw, and what to expect after you do.
CRY makes CRY Optimizer, a free Windows utility that reads and writes registry keys, configures services, and runs system commands. The design constraints that limit blast radius:
%LOCALAPPDATA%\CryOptimizer. It never leaves your PC.CRY is currently v1.1 BETA. There will be bugs. Report them.
Please report security issues privately by email to realwilari@gmail.com. Do not open a public issue, post details on social media, or share a working exploit before we've had a chance to fix the problem.
If you'd like to encrypt your report, a PGP key is available on request — email us at the address above and ask for it before sending sensitive details. For routine, non-sensitive reports, plain email is fine. This page is also referenced from our machine-readable security.txt file.
The more of the following you can give us, the faster we can confirm and fix the issue:
v1.1 BETA) and which surface is affected — the app, the portable build, or this website.Please do not include real personal data or other people's data in your report, and don't run tests against systems that aren't yours.
The following are in scope for a security report:
.zip — for example integrity, tampering, or unsafe handling of imported cryset: preset codes.al1.gg) and its content.If you're unsure whether something is in scope, email us and ask — we'd rather review a borderline report than miss a real one.
The following generally fall outside this policy. Reports limited to these are unlikely to be treated as security issues:
This list isn't exhaustive. When in doubt, ask.
We support good-faith security research. If you make a genuine, good-faith effort to follow this policy, we will not pursue or support legal action against you for your research, and we will treat your activity as authorized. To stay within safe harbor, please:
This safe harbor applies to the extent permitted by the applicable law of the jurisdiction in which CRY is established; nothing here authorizes activity that is unlawful or that targets third parties. If in doubt about whether an action is permitted, ask us first.
CRY is a small effort. The process below is what we can commit to, not a service-level guarantee:
If you don't hear back in a reasonable time, it's fine to send a polite follow-up to realwilari@gmail.com — messages occasionally get missed.
We ask that you give us a reasonable window to investigate and release a fix before any public disclosure, and that you don't publish details or working exploits that would put users at risk in the meantime. In return, we'll work the issue in good faith and keep you in the loop. Once a fix is available, we're happy to coordinate timing on any write-up or advisory, and to credit you if you'd like. We don't currently run a paid bug-bounty program, so reports are handled on a coordinated-disclosure basis rather than for a reward.
We're grateful to the researchers who report issues responsibly. If you report a valid vulnerability and would like public credit, tell us how you'd like to be named (handle, name, or a link) and we'll acknowledge your contribution when the fix is published. If you'd prefer to remain anonymous, that's completely fine — just say so.
For automated tooling, the canonical contact details live in our machine-readable policy file at /.well-known/security.txt, following the security.txt convention. It points back to realwilari@gmail.com and to this page. If the two ever disagree, the most recently updated version of this page takes precedence.