redshiftzero

Results 162 issues of redshiftzero

There is a lot of excellent and exhaustive documentation in the SecureDrop installation guide. As an administrator tasked with installing SecureDrop, when I begin the installation process, if I am...

information architecture

## Description Eventually we should also translate the SecureDrop source and journalist guides into our supported languages. [Some organizations](https://www.rise.md/leaks/) are doing this themselves e.g. [SecureDrop source guide in Romanian (PDF)](https://www.rise.md/leaks/securedrop-source-guide.ro.pdf)....

## Description We need **_clear step by step_** instructions how to reprovision journalist accounts after a reinstall. This should include how to safely transfer credentials to a remote journalists. ##...

needs/scoping

Some organizations may be unfamiliar with best practices around the acquisition, storage and transfer of secure hardware and associated secrets. To be clear, the hardware here includes the Secure Viewing...

In #53, several crates in this workspace (`poseidon-parameters`, `poseidon-permutation`, `poseidon377`) were rewritten to use const generics such that they can be used on embedded platforms. During that work, `poseidon-paramgen` was...

In #53, the crates in this workspace were rewritten to use const generics, for example the base `Matrix` became: ```rust pub struct Matrix { /// Elements of the matrix, stored...

There's another version of Poseidon, called Poseidon2: https://eprint.iacr.org/2023/323 Most relevant for us is section 7.3 which discusses mitigating the attacks found [here](https://tosc.iacr.org/index.php/ToSC/article/view/9850 ) where the researchers are able to skip...

We should add test vectors for the `EffectHash` mechanism for transaction signing, i.e. we should generate a bunch of random `TransactionPlan`s, compute their `EffectHash`, and add them as test vectors....

A-testing

**Is your feature request related to a problem? Please describe.** As of #4343, there is an option to encrypt the custody config file with a password such that it is...

E-easy
needs-refinement

Pointed out by @hdevalence: > If someone creates an address with a transmission key that is not a valid decaf377 encoding, sending an output to that address will crash the...

A-shielded-crypto
_P-low