-
Notifications
You must be signed in to change notification settings - Fork 343
Publish security audits #579
Comments
https://www.coronawarn.app/en/#privacy under the point "Security" also says: "Security assurance of application development through Secure Software Development Lifecycle, which includes among other things threat modeling and end-to-end risk assessment, security planning, security testing and penetration testing." I didn't find a link to these threat modelings, etc. there neither. |
That's great and interesting, but not really a security audit from an external company... |
@rugk I will try to get some info. Internal Tracking ID: EXPOSUREAPP-5956 |
Penetration test were also mentioned in https://dbtg.tv/cvid/7519454 at around minute 12. |
FYI the BSI responded to some FOI („freedome of information”, IFG - Informationsfreiheitsgesetz) request and thus published some audits: |
The BSI responded to a question I asked them on Twitter, it's not planned to publish the security audits ("Eine Veröffentlichung der Berichte als solches ist aktuell nicht geplant."). |
This is funny, because they actually did publish some of them in/via the FOI request above… 🙃 I asked them why they don't do this. 😅 |
Is the argument from the Twitter user a valid one? For me it sounds logically that they won't publish these audits because hackers then would know what doesn't work and can concentrate on other methods. But tbh I never read through a security audit so 🤷🏻♂️ |
@Ein-Tim I already replied on Twitter but the TLDR is, as you also said: Of course do not publish unfixed/undisclosed vulnerabilities. As for fixed ones, however, there is – judging from the technical experience – no disadvantage/risk of just publishing it. Especially as they, as you noticed, are already somewhat public on GitHub. |
@rugk I've raised the issue again, this time as a feature request.
It goes against all security best pratices, so no, it isn't really valid.
Corona-Warn-App Open Source Team |
Thank you for the explanation (and for rising this topic again)! |
Is there any update available here? Will security audits be published directly on GitHub or is it necessary to request them via a FOI request? |
Your Question
overview-security.md
As far as I read the doc there, you seem to acknowledge to do (external?) security audits of your code etc.
I'm talking about technical security audits (code audits/blackbox or whitebox-like etc.), not GDPR/privacy analyses/statements etc.
Internal Tracking-ID: EXPOSUREAPP-8354
The text was updated successfully, but these errors were encountered: