Skip to content
This repository has been archived by the owner on Jun 25, 2018. It is now read-only.

Document the security mechanisms used #54

Open
gggeek opened this issue Aug 18, 2015 · 0 comments
Open

Document the security mechanisms used #54

gggeek opened this issue Aug 18, 2015 · 0 comments
Milestone

Comments

@gggeek
Copy link

gggeek commented Aug 18, 2015

It would be nice to know a bit more about how encryption is used in this project, so that would-be users can evaluate it easily before adoption and testing.

Things like what data is encrypted, when and how, and what is not.

Having a threat model document would be wonderful, describing common attack scenarios and whether this app is good to prevent them. Such as:

  • network sniffing (esp. in cybercafe scenarios where a mitm could be done even if you are using https, via a malevolent dns server and stolen root certs)
  • reading data in-memory of the php app (or its logs and source code)
  • are the passwords safe from dbas or anyone stealing the db
  • etc...
@pklink pklink added this to the 1.0.0 milestone Aug 20, 2015
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

2 participants