YunoHost / issues

General issue tracker for the YunoHost project
72 stars 8 forks source link

"Security" and threat model tutorial #2332

Open tituspijean opened 9 months ago

tituspijean commented 9 months ago

(disclaimer, I have never done any thread model analysis)

Questions about doing things "securely" within and around YunoHost often come up in the forum and chat rooms. We even advertise YunoHost as aiming to "democratize self-hosting, while making sure it stays reliable, secure, ethical and lightweight" (emphasis mine).

I think it would be nice to have a FAQ entry or a dedicated page about what is "security", and how users should really think in terms of threat model, and how YunoHost defines and handles it, and how users should define and handle their own. The format could be in the likes of what we already do about DNS and certificates.

From the top of my mind we should clarify how data and processes are "secured" in the scope of:

*these could actually be also quoted in the packaging tutorials.

MathieuW commented 8 months ago

Not formally a threat model, but great risk management by DeuxFleurs : https://guide.deuxfleurs.fr/vie_associative/gestion-des-risques/