scidsg / hushline

Hush Line connects whistleblowers with organizations and people who can help.
https://hushline.app
GNU Affero General Public License v3.0
79 stars 21 forks source link

[Audit] - High-Level Checklist of Findings and Next Steps #247

Open glenn-sorrentino opened 9 months ago

glenn-sorrentino commented 9 months ago

Security Audit Action Items Checklist

Please note that this checklist is based on a general understanding of security best practices and the specific items discussed. It's important to tailor these action items to the specific findings and recommendations detailed in the security audit report.

glenn-sorrentino commented 9 months ago

Item 1: Investigate Potential DoS Vulnerability addressed by https://github.com/scidsg/hushline/issues/248

glenn-sorrentino commented 9 months ago

Item 5: Implement Rate Limiting and Monitoring addressed by https://github.com/scidsg/hushline/issues/241 https://github.com/scidsg/hushline/issues/243 https://github.com/scidsg/hushline/issues/244

glenn-sorrentino commented 9 months ago

Item 2: Review and Enhance Authentication Mechanisms addressed by https://github.com/scidsg/hushline/issues/240

glenn-sorrentino commented 9 months ago

Item 4: Update and Patch Systems addressed inherently through unattended upgrades

glenn-sorrentino commented 9 months ago

Review Third-party Services addressed.

glenn-sorrentino commented 9 months ago

Encrypt Sensitive Data addressed by