Skip to content
This repository was archived by the owner on Dec 19, 2024. It is now read-only.

SCP 008: Publish an invariant-centric threat model for OrbitDB #9

Open
holmesworcester wants to merge 1 commit intoorbitdb-archive:mainfrom
holmesworcester:main
Open

SCP 008: Publish an invariant-centric threat model for OrbitDB #9
holmesworcester wants to merge 1 commit intoorbitdb-archive:mainfrom
holmesworcester:main

Conversation

@holmesworcester
Copy link

This proposal is to draft, approve, publish, and maintain an invariant-centric threat model for OrbitDB—that is, a list of security invariants and known weaknesses of OrbitDB that can be easily understood by all users and stakeholders, from teams building products on OrbitDB, to security auditors of those products, to end users of those products.

See Invariant-Centric Threat Modeling for a more thorough explanation of this methodology and its advantages.

A draft threat model is included, along with proposed steps for publishing, auditing, and maintenance.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant