Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Create encryption keys amongst security@zfnd.org #1638

Open
Tracked by #3096
dconnolly opened this issue Jan 25, 2021 · 7 comments
Open
Tracked by #3096

Create encryption keys amongst security@zfnd.org #1638

dconnolly opened this issue Jan 25, 2021 · 7 comments
Assignees
Labels
A-docs Area: Documentation A-infrastructure Area: Infrastructure changes

Comments

@dconnolly
Copy link
Contributor

dconnolly commented Jan 25, 2021

And publish the public key in our responsible_disclosure.md statement. Ideally created on yubikeys, with backups. Elucidate the creation, rotation, and EOL'ing keys.

For now we have an old draft at: https://docs.google.com/document/d/1ORGAzAYq5vc86SxBlugYAE5daLbnTRCIZSELCvFKZaY

After discussion/review we should update the ticket text here

Quick consensus on tooling:

  • PGP for breadth
  • Optionally age for more experimental/modern researchers, but not primary
@dconnolly dconnolly added A-docs Area: Documentation A-infrastructure Area: Infrastructure changes labels Jan 25, 2021
dconnolly added a commit that referenced this issue Jan 25, 2021
Update when we generate keys

#1638
dconnolly added a commit that referenced this issue Jan 25, 2021
Update when we generate keys

#1638
@teor2345 teor2345 added this to the 2021 Sprint 15 milestone May 10, 2021
@teor2345
Copy link
Contributor

Putting this in the last sprint, so we remember to do it before mainnet activation.

@teor2345 teor2345 removed this from the 2021 Sprint 15 milestone Jun 24, 2021
@mpguerra mpguerra added this to the 2021 Sprint 24 milestone Oct 13, 2021
@mpguerra
Copy link
Contributor

mpguerra commented Nov 1, 2021

Do we still want to/need to do this?

@teor2345
Copy link
Contributor

We're getting closer to the stable release candidate series, so this is a medium priority now.

@dconnolly dconnolly changed the title Create PGP keys amongst security@zfnd.org Create encryption keys amongst security@zfnd.org Jun 19, 2023
@teor2345
Copy link
Contributor

Here are some reasons to make our first secure contact method a PGP key:

If we want to get the same disclosures as zcashd:
https://github.com/zcash/zcash/blob/master/SECURITY.md#receiving-disclosures

If we want to conform to accepted responsible disclosure standards within the cryptocurrency community:
https://github.com/RD-Crypto-Spec/Responsible-Disclosure/tree/d47a5a3dafa5942c8849a93441745fdd186731e6#giving-details

We can add additional secure contact methods, but in my opinion they should be separate tickets. That allows us to give them different schedules and priorities.

@dconnolly
Copy link
Contributor Author

dconnolly commented Jun 20, 2023

@mpguerra mpguerra self-assigned this Jul 19, 2023
@mpguerra
Copy link
Contributor

I've started coordinating on this

@mpguerra
Copy link
Contributor

removing from sprint, I still have it on my to do list to do asap

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
A-docs Area: Documentation A-infrastructure Area: Infrastructure changes
Projects
Status: Sprint Backlog
Development

No branches or pull requests

3 participants