-
Notifications
You must be signed in to change notification settings - Fork 38.8k
Mention reporting security issues responsibly #9115
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
|
Concept ACK, though, this reminds me, that we should offer a way how users can send encrypted mails to [email protected] |
|
Concept ACK.
This is a challenge in itself. I know of no way to do encrypted group addresses. Some security reporting addresses use a shared private GPG key specifically generated for that purpose, but after retiring the alert key we're probably not too happy to adapt private shared keys. Though this one would be used for reading mail only I guess... |
|
Yes. It's a challenge and involves writing to specific developers. |
|
Yes, this discussion belongs there. But... It would be nice to be able to encrypt such message inside the Bitcoin Core UI, using 1-of-n concept. |
.github/ISSUE_TEMPLATE.md
Outdated
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Indeed. The discussion belongs there, and so does the documentation. Maybe refer to the instructions for reporting security issues on the contact page: https://bitcoincore.org/en/contact/ instead of mentioning the address directly?
If we then happen to have GPG set up, it can be mentioned there without having to put everything into this template.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I wanted to do so first, but the URLs are fragile and can change. And when the separate "Report security issues" page happens at bitcoincore.org, we will have to change URL here. Mail will probably be the same.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I think https://bitcoincore.org/en/contact/ will always be the page for contact, even if there is a subsection with a list of gpg keys.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
How can you predict it will be a subsection? What if en-GB speakers will ask for en-GB and en-US page?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
"I wanted to do so first, but the URLs are fragile and can change" so are email addresses.
It's not impossible to update this again, it just should be rare.
ac859f6 to
7d1de30
Compare
|
OK, OK ;-) |
|
ACK 7d1de30 |
7d1de30 Mention reporting security issues responsibly (Pavel Janík)
7d1de30 Mention reporting security issues responsibly (Pavel Janík)
7d1de30 Mention reporting security issues responsibly (Pavel Janík)
Add a notice about reporting security issues responsibly to the GitHub issue template.