nthdimtech / signet-base

Signet firmware and device interface library
https://www.crowdsupply.com/nth-dimension/signet
GNU General Public License v3.0
15 stars 7 forks source link

Idea: Potential stretch goal on Crowdsupply: independent security audit #12

Open dumblob opened 6 years ago

dumblob commented 6 years ago

An independent security audit at some point in the future would be awesome.

Btw I've heard about Mozilla giving grants to projects having something to do with web and security - Signet could actually satisfy these requirements and thus might be worth taking a look at :wink:.

nthdimtech commented 6 years ago

Interesting, I'll look into it. I would like to have it audited some point after I've put most of the security features I have planned. I'm not sure about the logistics of it though. I think it would be the most credible if I nether asked for or paid for it. By that theory the only thing to do is wait for it to occur after the project reached a certain level of popularity.

One thing I want to do to encourage an audit though is to produce one or more documents providing my own analysis of its security which could be a more approachable starting point for an audit than just the code.

On November 11, 2017 2:41:45 PM PST, dumblob notifications@github.com wrote:

An independent security audit at some point in the future would be awesome.

Btw I've heard about Mozilla giving grants to projects having something to do with web and security - Signet could actually satisfy these requirements and thus might be worth taking a look at :wink:.

-- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/nthdimtech/signet-firmware/issues/12

-- Sent from my Android device with K-9 Mail. Please excuse my brevity.

dumblob commented 6 years ago

One thing I want to do to encourage an audit though is to produce one or more documents providing my own analysis of its security which could be a more approachable starting point for an audit than just the code.

That's definitely a very good idea.

Thanks!

dumblob commented 5 years ago

Any news here? I saw some "results of an audit" in a commit message, but the changes didn't look like an overall audit with publicly available results documentation.

nthdimtech commented 5 years ago

That was just some double checking on my part and not meant to address this bug. Thanks for the reminder on this one. I should at least draft a document on Signet's security model before I move on to Signet HC. Much will be shared between the devices in this respect anyways