HiveMinds / HiveMinds/tw-install
Explain security weaknesses of the automatic installation procedure.
- Dominant language
- Shell
- Stars
- 20
- Forks
- 7
- PR merge metrics
- No merged PRs in 30d
Description
Develop a better understanding of the consequences for the security of your taskwarrior data, and your device in general based on the design choices made in the implementation of the automatic installation.
Key topics in this perspective are:
- The current certificate trust setting is not set to strict as recommended on: https://gitpitch.com/GothenburgBitFactory/taskserver-setup#/14/7
- What is the consequence of not using Let's Encrypt as listed on: https://gitpitch.com/GothenburgBitFactory/taskserver-setup#/13/4
- The current certificate validation procedure in light of: https://gitpitch.com/GothenburgBitFactory/taskserver-setup#/9/2
Contributor guide
No contributing guide indexed for this repository
Research direction
Read the automatic installation implementation and the three linked GitPitch sections on certificate trust, Let's Encrypt, and certificate validation. Document the security consequences for Taskwarrior data and the device, covering each listed topic; the issue is done when those weaknesses and their implications are clearly explained.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- shell
- Domain
- devops, security
- Issue type
- Documentation
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100