ethereum-oasis-op / baseline-standard

Repository for the Baseline standards team and specification work
Creative Commons Zero v1.0 Universal
18 stars 33 forks source link

R12 requirement is not prescriptive enough #134

Closed atoulme closed 2 years ago

atoulme commented 2 years ago

R12 states "A BPI MUST support cryptographic algorithms based on commonly used and security-audited libraries."

Is there a way to be more precise here? Can this refer to controls that are more specific to the use of cryptography in Baseline?

atoulme commented 2 years ago

R14 feels more adequate and precise than R12.

chaals commented 2 years ago

Agree R14 is better, but that's also pretty vague. Certainly there is no obvious need for both.

Therecanbeonlyone1969 commented 2 years ago

Closing. Addressed with merged PR https://github.com/eea-oasis/baseline-standard/pull/173