NixOS Marketing | 243 Members | |
| NixOS website + marketing team: https://nixos.org/community/teams/marketing.html | 53 Servers |
| Sender | Message | Time |
|---|---|---|
| 27 Nov 2024 | ||
Download image.png | 01:38:26 | |
| security is already down here | 01:38:30 | |
| we already get lots of useful reports | 01:38:34 | |
| implementing well-known security is what is currently missing | 01:40:16 | |
| https://en.wikipedia.org/wiki/Security.txt | 01:41:03 | |
| https://datatracker.ietf.org/doc/html/rfc9116 | 01:41:15 | |
| you kinda went in without a concrete plan | 01:41:41 | |
| prior art was linked early on and not acted upon | 01:42:01 | |
| I was asking for a plan, and the information you just gave me--which would've been helpful to have on a comment on that PR--is a big help. Thank you! | 01:42:05 | |
| There's another philosophical question which is: would it be a good idea to put security right on the navbar? My personal bet is yes, because:
| 01:45:33 | |
Uh … what? | 01:46:31 | |
| I don't mind whether it is down there or up there, but the start page mentions security a bit too much | 01:47:15 | |
Download image.png | 01:47:18 | |
| moving it up would improve the tab order | 01:47:36 | |
| Sure, and we could probably stand to ditch a tab or two as well...it is a little busy. | 01:48:02 | |
| (and again, I'm not wed to this, just kicking around an idea) | 01:48:19 | |
| Hmmm, at some point we maybe should consider some kind of drop down menu for the main nav, otherwise this would clog up a lot | 01:49:01 | |
Download image.png | 01:49:27 | |
| so that's what we have right now | 01:49:31 | |
| Yup | 01:51:25 | |
| 01:52:07 | |
| and like, I know folks put effort into these pages at one time or another, so I don't want to just bulldoze that | 01:52:29 | |
| but uh, there's some prime real estate that could probably use redevelopment | 01:52:42 | |
| back to the security thing, my issues with the current team page are basically:
Of these, the easiest fix is the first--the second requires a bit more coordination and the third would be a big change over on the security team I think. So, I was just trying to pull on the first thread mainly. | 01:59:28 | |
| (and yes, I know that the "if you want to report..." does technically exist. never underestimate the ability of users to do the wrong thing when presented with something that isn't a flowchart with blinking lights and monosyllables. I include myself in that population.) | 02:00:44 | |
| There is trade-offs in reporting. We support encrypted reports through GPG and we just won't manage a shared key. We could make more use of the security@ alias for everything else though. | 02:01:26 | |
| I was thinking of a very specific workflow:
I'm not sure how that would interact with the GPG thing, but I'm also not really sure that GPG is as important as a redundant and auditable comms. | 02:05:02 | |
| ("normal channels" here being GPG email or what have you) | 02:05:39 | |
| I'm not sure that an audit trail is high on our list of priorities, and we generously cc reports between team members either way | 02:06:16 | |
| it is how we track whether a thing was actually replied to | 02:07:20 | |