shadowsocks / shadowsocks/shadowsocks-org

Threat Model

Open
#62 12 comments 7 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

enhancement
Dominant language
HTML
Stars
1k
Forks
694
PR merge metrics
No merged PRs in 30d

Description

I propose we document the Threat Model of the Shadowsocks project. The Threat Model should explain the scenarios to design for, and the assumptions about users, operators, and adversaries. It should help us better understand the goal of the project, and resolve conflicts and disputes in discussions.

At minimal, the Thread Model must answer the following questions (order does not matter):

  • Who are the users?
  • Why and how do they use our software?
  • Who are the adversaries?
  • Why and how do they attack the users?
  • How do we differ from other similar projects (e.g. OpenVPN and Tor)?

This is a very rough proposal. Please comment for feedback.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No file or test is identified; start by reviewing the project documentation and the discussion on this issue. Define the threat model around users, usage, adversaries, attacks, assumptions, and differences from OpenVPN and Tor. Done means the resulting document answers each listed question and resolves the stated scope clearly.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.