zebra icon indicating copy to clipboard operation
zebra copied to clipboard

Create encryption keys amongst [email protected]

Open dconnolly opened this issue 3 years ago • 7 comments

And publish the public key in our responsible_disclosure.md statement. Ideally created on yubikeys, with backups. Elucidate the creation, rotation, and EOL'ing keys.

For now we have an old draft at: https://docs.google.com/document/d/1ORGAzAYq5vc86SxBlugYAE5daLbnTRCIZSELCvFKZaY

After discussion/review we should update the ticket text here

Quick consensus on tooling:

  • PGP for breadth
  • Optionally age for more experimental/modern researchers, but not primary

dconnolly avatar Jan 25 '21 20:01 dconnolly

Putting this in the last sprint, so we remember to do it before mainnet activation.

teor2345 avatar May 10 '21 00:05 teor2345

Do we still want to/need to do this?

mpguerra avatar Nov 01 '21 16:11 mpguerra

We're getting closer to the stable release candidate series, so this is a medium priority now.

teor2345 avatar Jul 27 '22 22:07 teor2345

Here are some reasons to make our first secure contact method a PGP key:

If we want to get the same disclosures as zcashd: https://github.com/zcash/zcash/blob/master/SECURITY.md#receiving-disclosures

If we want to conform to accepted responsible disclosure standards within the cryptocurrency community: https://github.com/RD-Crypto-Spec/Responsible-Disclosure/tree/d47a5a3dafa5942c8849a93441745fdd186731e6#giving-details

We can add additional secure contact methods, but in my opinion they should be separate tickets. That allows us to give them different schedules and priorities.

teor2345 avatar Jun 20 '23 04:06 teor2345

Some resources:

  • https://developers.yubico.com/PGP/PGP_Walk-Through.html
  • PGP keys can be stored in 1Password as attachments or secure notes
  • https://support.yubico.com/hc/en-us/articles/360013790259-Using-Your-YubiKey-with-OpenPGP
  • https://medium.com/cloud-security/storing-a-gpg-pgp-key-on-a-yubikey-905a8fe8dad7

dconnolly avatar Jun 20 '23 21:06 dconnolly

I've started coordinating on this

mpguerra avatar Jul 19 '23 09:07 mpguerra

removing from sprint, I still have it on my to do list to do asap

mpguerra avatar Sep 13 '23 08:09 mpguerra