Skip to content

content(opsec): endpoint security tiers and DPRK liveness verification#400

Open
artemisclaw82 wants to merge 9 commits intosecurity-alliance:developfrom
artemisclaw82:content/workforce-verification
Open

content(opsec): endpoint security tiers and DPRK liveness verification#400
artemisclaw82 wants to merge 9 commits intosecurity-alliance:developfrom
artemisclaw82:content/workforce-verification

Conversation

@artemisclaw82
Copy link

@artemisclaw82 artemisclaw82 commented Mar 1, 2026

Changes:

  • Endpoint Security (opsec/endpoint/overview.mdx): Device provisioning tiers (managed devices, VDI, enterprise browsers) for Web3 organizations, with role-based recommendations and comparison table.
  • DPRK Liveness Verification (techniques-tactics-and-procedures.mdx): Added deepfake detection techniques (head turn, random phrase, hand movement, live screen-share) under the 'Am I Interviewing a DPRK IT Worker?' section.
  • DPRK Mitigations (mitigating-dprk-it-workers.mdx): Removed contributed role that didn't apply.

Authors: @DicksonWu654, @andrew-chang-gu

@github-actions
Copy link

github-actions bot commented Mar 1, 2026

Sidebar Configuration Reminder

Documentation files update:

New in this push:

  • docs/pages/opsec/secure-operating-systems.mdx (added) ← NEW

Please ensure that:

  • The sidebar in vocs.config.tsx has been updated to include these files
  • New content has the dev: true parameter so it's marked as under development
  • Sidebar links match the file paths - use the preview deployment to verify

See Contributing Guide – Sidebar & Navigation for more details.


This is an automated reminder. If this PR doesn't need sidebar changes, you can ignore this message.

…boarding

Adds workforce security content from Andrew Chang-Gu (CISSP) presentation:
- 3-level identity verification framework (pseudonymous → verified → privileged)
- Anti-deepfake liveness techniques for video interviews
- Hardened onboarding sequence (identity → environment → scoped access)
- Instant offboarding procedure (IdP → sessions → secrets → hardware → audit)
@artemisclaw82 artemisclaw82 force-pushed the content/workforce-verification branch from 6203ca9 to 54a8287 Compare March 1, 2026 05:38
@artemisclaw82
Copy link
Author

Updated — PR now only touches the DPRK mitigation page (1 file, 58 lines added). Device security tiers saved for a follow-up after PR #381 merges (the secure OS file only exists there).

artemisclaw82 and others added 2 commits March 1, 2026 21:18
- Remove Hardened Onboarding section (duplicates existing 'Hardening your organization')
- Remove Instant Offboarding section (duplicates existing 'I hired a DPRK IT Worker')
- Trim Liveness Verification intro (cross-reference TTP page instead of restating)
- Add cumulative tier checks (Level 2 includes Level 1, Level 3 includes Level 2)
- Add Device Security Tiers section (Managed Devices, VDI, Enterprise Browser)
  moved from secure-operating-systems PR to keep all Andrew content together

Co-authored-by: Dickson Wu <dicksonwu654@users.noreply.github.com>
Device provisioning tiers (Managed Devices, VDI, Enterprise Browser) are
general organizational security guidance, not DPRK-specific. Move from
the DPRK mitigation page to the Endpoint Security page where it belongs.

Replaces the placeholder content with a full page including a comparison
table and cross-references to related sections.

Co-authored-by: Dickson Wu <dicksonwu654@users.noreply.github.com>
@DicksonWu654
Copy link
Collaborator

Let's update the name of the PR plz

Per review: removed 'Defeating Deepfakes' section and 'periodic re-verification' bullet
from mitigating page. Moved liveness content to TTP page under 'Am I Interviewing' section
where it contextually belongs.
@github-actions
Copy link

github-actions bot commented Mar 2, 2026

Sidebar Configuration Reminder

Documentation files update:

New in this push:

  • docs/pages/config/index.mdx (added) ← NEW

Please ensure that:

  • The sidebar in vocs.config.tsx has been updated to include these files
  • New content has the dev: true parameter so it's marked as under development
  • Sidebar links match the file paths - use the preview deployment to verify

See Contributing Guide – Sidebar & Navigation for more details.


This is an automated reminder. If this PR doesn't need sidebar changes, you can ignore this message.

@artemisclaw82 artemisclaw82 changed the title content(dprk): add tiered verification, liveness checks, and onboarding/offboarding content(dprk): add tiered identity verification framework Mar 2, 2026
Remove unrelated config index and endpoint overview changes so this PR only includes DPRK mitigation/TTP updates from review feedback.
Per review: removed '### Tiered Identity Verification' section from mitigating page.
Restored endpoint/overview.mdx with device security tiers and attribution.
@DicksonWu654
Copy link
Collaborator

update title and description

@artemisclaw82 artemisclaw82 changed the title content(dprk): add tiered identity verification framework content(opsec): endpoint security tiers and DPRK liveness verification Mar 2, 2026
…endpoint overview

Per review: removed andrew-chang-gu contributed attribution from DPRK mitigating page.
Replaced all emoji markers (✅⚠️🔑💡❌) with plain text in endpoint overview.
Copy link
Collaborator

@DicksonWu654 DicksonWu654 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yay lgtm now!

@DicksonWu654
Copy link
Collaborator

plz undraft now!

@artemisclaw82 artemisclaw82 marked this pull request as ready for review March 2, 2026 06:00
@github-actions
Copy link

github-actions bot commented Mar 2, 2026

built with Refined Cloudflare Pages Action

⚡ Cloudflare Pages Deployment

Name Status Preview Last Commit
frameworks ✅ Ready (View Log) Visit Preview 46c88fa

@scode2277 scode2277 added content:add This issue or PR adds content or suggests to labels Mar 2, 2026
Comment on lines +697 to +708
"andrew-chang-gu": {
"slug": "andrew-chang-gu",
"name": "Andrew Chang-Gu",
"avatar": "https://avatars.githubusercontent.com/andrew-chang-gu",
"github": "",
"twitter": "",
"website": "",
"company": "",
"job_title": "",
"role": "contributor",
"description": "",
"badges": []
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please revert all the indentation updates regarding the other users + @DicksonWu654 what is the actual github username of Andrew? The user added doesn't seem to exist

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

content:add This issue or PR adds content or suggests to

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants