Skip to content
This repository has been archived by the owner on Sep 19, 2024. It is now read-only.

RD AD comments on Security Considerations #407

Open
mcr opened this issue May 4, 2022 · 1 comment
Open

RD AD comments on Security Considerations #407

mcr opened this issue May 4, 2022 · 1 comment
Assignees
Labels
wontfix Should respond via email but does not warrant doc changes

Comments

@mcr
Copy link
Collaborator

mcr commented May 4, 2022

[Roman's comments on -13]
I didn't come away from this section with a strong, consistent understanding of which interactions needs which security properties or what considerations are need for which roles. Section 12.2 is at least clear on integrity, but it also makes vague allusions to other properties.

-- Section 12.2 This section lists that there might be a need to support additional security properties and provides list (i.e., E2E encryption, DoS protection, authentication, etc.) . What actionable guidance should be taken from this text? How should one reason about those properties?

-- The overall Section 12 seems silent on:

o Endorsers and endorsements?
o Reference values?
o What is the implication of combining roles into a single entity as described in Section 3.4 and 6. Does this lack of separation present any additional issues?
o Compositional devices per Section 3.3?

[Roman's comment on -15]
I didn't see any discussion on text changes in this section related to these comments. I saw #367 which seemed to match this feedback, but the associated pull request seemed to fix an editorial issue.

@mcr
Copy link
Collaborator Author

mcr commented May 10, 2022

We need to acknowledge that there is a deep hole (not infinitely deep, but not trivial) where we need to look at integrity of all of the different platforms.
The way that the compositions are composed is a bit tricky, and the results are sometimes different than other people would naively assume.
Are there references here to other papers that we should include?

@mcr mcr added the wontfix Should respond via email but does not warrant doc changes label May 24, 2022
@mcr mcr self-assigned this May 24, 2022
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
wontfix Should respond via email but does not warrant doc changes
Projects
None yet
Development

No branches or pull requests

1 participant