-
Notifications
You must be signed in to change notification settings - Fork 75
Update VRP point of contacts #1195
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Conversation
|
Luigi forwards emails of people who have issues registering on the ccs repo so the email is actively read, he's a member of core and is intimately involved with the VRP. If the email / rsa2048 is the issue please convince him its critical. Is RSA 2048 deprecated now or in 2030 due to quantum computing? (Ive only scanned a hacker one post about it) if so, what encryption should be used? The new key would then have appropriate encryption/email. |
Thanks for confirming this is actively read. I assume an entire day passing without any response to be of concerns when the rsa key is "outdated in today's standard". And I have no doubt he is involved since he is the one paying out the bounty, tho he could also just be busy with other things.
Imo the key issue is not a matter of cryptography tho i would welcome any more qbit work needed. Monero is a privacy cryptocurrency which have to put an accent on security. This can be seen with numerous audits and the talented devs. I, and I think others, would expect the VRP to be coherent with the general project standards, and having an up to date key is the bare minimum for any project. I know its boring, but please @luigi1111 regenerate an RSA-4096 PGP keypair, with a 4 years lifetime, against [email protected] (and your gmail as another uid if you need it for forward i suppose). |
| ``` | ||
|
|
||
| ## II. Security response team |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
There are more people that have access to the HackerOne, so how exactly is security reponse team defined?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I would assume anyone who have access to the report without being invited.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
In this case I would keep luigi. serhack also has access, though I'm not sure how active he is currently.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
ngl I never heard of serhack, I'll just keep luigi
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Only seen them on Reddit before
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Everyone's heard of serhack 😅
among other things, is the author of Mastering Monero
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Everyone's heard of serhack 😅
among other things, is the author of Mastering Monero
ah alright lol. i guess he can be listed
Breaking NewsYet another person got confused over the PGP keys |
|
A couple points: My involvement with VRP has historically mostly been paying out bounties for valid reports. I don't particularly want to be a primary point of contact for vulnerability reports outside of Hackerone. I'm interested to learn of/participate in critical, particularly consensus-breaking bugs, but not much else. getmonero email is a spam fest, almost unusable. I don't monitor the inbox very closely and don't run the server. Lastly, I agree I need to update gpg keys, but prefer to do against gmail and curve25519 for Github signing rather than vulnerability reports, though it could be used for that. |
That's understandable,
If you don't particularly wish to be a primary point of contact then there should be a discussion about who could and would be willing to do it.
Fair enough |
|
jeffro would be a reasonable candidate if willing. Could possibly make it part of CCS to "ensure" someone has incentive to monitor for any reports? A couple other long term devs come to mind as well, but I don't know if they have any interest. |
Mind listing the devs in question? might as well directly ask them in #monero-dev. This could spark a discussion. |
|
I thought of vtnerd, but in theory the other devs that are on 5+ repeat hourly CCSes would be candidates. Not sure how many that is. |
I somehow forgot about vtnerd even tho he is handling 80% of the vuln reports lmao |
|
The workload for the point of contact should be low, from what I can tell almost all reports happen over HackerOne. |
|
Devs with >5 CCS' (num)
|
|
I'm willing to include being a point of contact as part of my next CCS |
|
this so much true. @Boog900 should rule the world |
|
I was mentioned above - I can go on the VRP list if useful. I assume this means I would finally need to complete my GPG setup? |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
sorry,inore my approval,thank you!
will squash once approved
Luigi don't respond to emails
and the pgp key have already caused numerous confusions:
#164 (comment)
https://hackerone.com/reports/2677306#activity-29266850
https://libera.monerologs.net/monero-dev/20241222#c478888