theupdateframework / theupdateframework/specification

Add key compromise analysis section for top-level roles.

Open
#204 0 comments 3 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

enhancement
Dominant language
Python
Stars
405
Forks
59
Avg merge
3d 4h
Merged PRs (30d)
1

Description

I suggest to add a simple key compromise analysis section for the top-level roles akin to the corresponding sections in PEP 458 and PEP 480. That is a matrix that shows what type of keys an attacker needs to compromise in order to successfully perform a given attack.

The 2.2. Threat model and analysis should be a good place for this.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with section 2.2, “Threat model and analysis,” and compare its treatment of top-level roles with the key compromise analysis sections in PEP 458 and PEP 480. Identify the relevant attack types and key categories from the specification, then document them in a matrix showing which compromises enable each attack. Done means the section clearly covers the top-level roles and their attack requirements.

Written by the indexing model from the issue text.

Assessment

Domain
documentation
Issue type
Documentation
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.