Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Introduce [email protected] as security contact #9690

Merged
merged 1 commit into from
Nov 6, 2024

Conversation

pabzm
Copy link
Member

@pabzm pabzm commented Nov 5, 2024

Using a dedicated email address with a dedicated PGP key allows to give multiple people access while still keeping things under wrap.

A single, private email address as security contact is such a huge bus factor, which we should avoid. Event just a holiday or illness could lead to escalation due to missing replies.

Also, in case of potentially severe security issues Nextcloud's security team must have access to all details and communication. This is already given for all issues reported via hackerone.com, and with this change is now also enabled for issues reported by email.

@pabzm
Copy link
Member Author

pabzm commented Nov 5, 2024

@alecpl I'll provide you with the IMAP credentials and the PGP private key as soon as this is merged. Please let us know what you think.

@pabzm
Copy link
Member Author

pabzm commented Nov 5, 2024

Related: roundcube/roundcube.github.com#67

Using a dedicated email address with a dedicated PGP key allows to give
multiple people access while still keeping things under wrap.

A single, private email address as security contact is such a huge bus
factor, which we should avoid. Event just a holiday or illness could
lead to escalation due to missing replies.

Also, in case of potentially severe security issues Nextcloud's security
team must have access to all details and communication. This is already
given for all issues reported via hackerone.com, and with this change is
now also enabled for issues reported by email.
@pabzm pabzm force-pushed the security-at-roundcube-dot-net branch from 59d7258 to 0440792 Compare November 5, 2024 13:51
@alecpl
Copy link
Member

alecpl commented Nov 6, 2024

I'm fine with it.

@pabzm pabzm merged commit 839694e into master Nov 6, 2024
33 checks passed
@pabzm
Copy link
Member Author

pabzm commented Nov 11, 2024

@alecpl I'll provide you with the IMAP credentials and the PGP private key as soon as this is merged. Please let us know what you think.

@alecpl This ist still on my list, currently blocked by an email system problem. Sorry!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants