Publish a what-we-do-not-protect-against page #97
Labels
No labels
area:docs
area:identity
area:ops
area:plugin
area:server
channel:community
channel:direct
channel:owned
channel:press
channel:social
e2ee-constrained
gate:at-ga
gate:pre-ga
marketing
parity
relay:absent
relay:planned
relay:requested
relay:supported
risk:additive
risk:contract
risk:none
usability
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
Nectenda/nectenda#97
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Why
The single highest-credibility asset available to this product with this
audience, and most vendors will not publish one. For a buyer who evaluates
security claims professionally, a published list of what a product does not
protect against is worth more than any amount of assurance.
The landing page already carries a short "What it does not claim" block. This is
the full version, and it has a gap in it that matters.
What to do
A page distilled from
docs/security-model.md(the caveats at lines 102-140 and226-276):
stored.
all in. Measured, not assumed.
is the same reason we cannot read your notes.
The item that is not published anywhere yet
docs/launch-readiness.mdGate E records it in as many words:The client reports its own crashes to a self-hosted error tracker when signed in
to the hosted service. It is off in one click. This is exactly the kind of
thing a security audience finds by watching traffic and then never trusts you
again for not having said first. Say it first, say where the reports go, and
say how to turn it off.
Constraints
page()throws.more than the page ever earned.
Also record
A trigger for commissioning a real third-party audit, rather than leaving it
open-ended. Suggested: the first of 25 paying organisations or €15k ARR. A
protocol/crypto audit runs roughly €10k–40k, which is not spendable before any
customer conversation has happened.
Moved to the Vikunja board as NEC-73: https://projectron.nerchure.com/tasks/73