gratipay / gratipay.com

Here lieth a pioneer in open source sustainability. RIP
https://gratipay.news/the-end-cbfba8f50981
MIT License
1.12k stars 308 forks source link

update PGP key #3174

Closed chadwhitacre closed 9 years ago

chadwhitacre commented 9 years ago

Mine expired a couple days ago:

http://pgp.mit.edu/pks/lookup?op=vindex&search=0x6EE18A8DC47977C2

blrhc commented 9 years ago

This is pretty easy to do isn't it?

chadwhitacre commented 9 years ago

Should be. It's probably a good time to move from chad@zetaweb.com to security@gratipay.com, too, though. No?

chadwhitacre commented 9 years ago

/me reviews https://www.gnupg.org/gph/en/manual/c14.html

chadwhitacre commented 9 years ago

@benhc123 Want to work on this one with me? Let's set up security@gratipay.com and make a key for that that both you and I have access to. Waddya say? :)

chadwhitacre commented 9 years ago

I've created the security user in Google Apps, but I'm having trouble delegating access to it to my main Gmail account, which is how I have the others set up.

chadwhitacre commented 9 years ago

Once security is configured at Google the next step is to configure it at Freshdesk. That's where I'll give you access, @benhc123.

chadwhitacre commented 9 years ago

I just tried delegation again and it went through. Maybe it took time for the new account to propagate within Google? :fried_shrimp:

chadwhitacre commented 9 years ago

Okay, I've configured security@gratipay.com in Freshdesk. I've also made a security team on GitHub and a security group at Freshdesk with @benhc123 @greggles @Changaco and myself.

chadwhitacre commented 9 years ago

@benhc123 Can I put you in charge of making a PGP key for security@gratipay.com?

chadwhitacre commented 9 years ago

I'm looking at this. I'm writing up an IG doc as I go.

chadwhitacre commented 9 years ago

Is maintaining PGP worth it? Rarely have security researchers used PGP during disclosure to us.

chadwhitacre commented 9 years ago

GitHub discourages encrypted email for security disclosures:

Where is your PGP key? I want to use it when I submit a vulnerability.

If you absolutely believe encrypting the message is necessary, please read our instructions and caveats for PGP submissions.

greggles commented 9 years ago

Does gratipay use a web-based form for submitting issues? If so I think that github page applies. Otherwise, the first paragraph and basis of their philosophy disappears ;)

greggles commented 9 years ago

That said...I also think that encrypted submissions are kinda silly.

chadwhitacre commented 9 years ago

But that's because they have a secure form on a website:

https://bounty.github.com/submit-a-vulnerability.html

As does Facebook: https://www.facebook.com/whitehat/report/.

chadwhitacre commented 9 years ago

Does gratipay use a web-based form for submitting issues? If so I think that github page applies. Otherwise, the first paragraph and basis of their philosophy disappears ;)

Right. ;-)