openid / openid/fapi

Explict security target

Open
#506 13 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

component: CIBA migrated-from-bitbucket priority: major type: enhancement
Dominant language
HTML
Stars
4
Forks
3
PR merge metrics
No merged PRs in 30d

Description

Originally submitted by Nat (Nat Sakimura) on 2022-06-28

When writing security and privacy considerations, explicit security and privacy assumptions and target would definitely help. Right now, we have attacker models but we do not have these.

We probably should have it earlier. It would have made the formal verification easier. Now that security researchers are working on the formal model, perhaps we can just have a rough text on it and later replace it with what security researchers come up with.

One of the deficiencies of FAPI 1.0 is that we actually do not have spelt out the security assumptions and target. We should make sure that we do it in FAPI 2.0.


Bitbucket status: open

Bitbucket origin: issue 506

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing the FAPI 2.0 security and privacy considerations alongside the existing attacker models. Define the explicit security and privacy assumptions and target, and ensure the resulting text can later align with the formal model produced by security researchers.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.