Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Assert Proposal 104 #2767

Closed
wants to merge 1 commit into from
Closed

Assert Proposal 104 #2767

wants to merge 1 commit into from

Conversation

faddat
Copy link
Contributor

@faddat faddat commented Oct 19, 2023

Description

It is our determination that the current security policy document on this repository represents a risk to the cosmos hub due to the release of information that can lead to chain halts, eg: "affect consensus participation" by informal systems and amulet, without review of documentation submitted by researchers at notional.

During the process of reporting a complex security issue, both informal systems and amulet have been entirely non-responsive. In total, notional has received three emails pursuant to this issue from amulet.

Because this issue extended over multiple layers of the cosmos stack, we initially chose to involve amulet because their job description with the foundation is security coordination. Unfortunately, that has not been occurring.

It is our opinion that individuals or organizations with security matters to report, who wish to be able to review any findings before publication, likely would not want to work with amulet and informal, due to the fact that amulet published our findings against our express wishes.

Rejection of this pull request would be in clear violation of cosmos hub governance, which has chosen notional to handle security operations for the cosmos hub.

Illustration

image

Most cosmos chains would have this reaction to the exploitation of the issue that was published by ICFormulet as low severity, so we're going to need to remove ICFormulet from the security flow for the hub, for the hub's sake. And for the rest of cosmos.


Author Checklist

All items are required. Please add a note to the item if the item is not applicable and
please add links to any relevant follow up issues.

I have...

  • included the correct docs: prefix in the PR title
  • targeted the correct branch (see PR Targeting)
  • provided a link to the relevant issue or specification
  • reviewed "Files changed" and left comments if necessary
  • confirmed all CI checks have passed

Reviewers Checklist

All items are required. Please add a note if the item is not applicable and please add
your handle next to the items reviewed if you only reviewed selected items.

I have...

  • Confirmed the correct docs: prefix in the PR title
  • Confirmed all author checklist items have been addressed
  • Confirmed that this PR only changes documentation
  • Reviewed content for consistency
  • Reviewed content for thoroughness
  • Reviewed content for spelling and grammar
  • Tested instructions (if applicable)

@faddat
Copy link
Contributor Author

faddat commented Oct 20, 2023

Hey I just want to let you know that if this does not end up getting merged, I'll take additional steps via governance that ensures that this is no longer the hub official repository, because governance is supposed to drive the hub, not ICFormulet.

@faddat
Copy link
Contributor Author

faddat commented Oct 20, 2023

@faddat
Copy link
Contributor Author

faddat commented Oct 20, 2023

@jessica0f0116
Copy link

Bluntly as a security researcher I think this kind of abusive, bullying behavior will discourage people from disclosing vulnerabilities. It's unkind to maintainers and a misuse of the PR system. faddat seems like someone influential who could make peoples lives difficult (and pretty well-resourced based on the contents of the referenced proposal). So I think I would just avoid any involvement in all of (gestures) this. it's gotten out of hand

@faddat
Copy link
Contributor Author

faddat commented Oct 22, 2023

Hi, no worries I'm going to show you abusive. But please keep in mind I'm not the one being abusive here's Ethan Buchman -- who is much more influential than myself, and much more well-resourced.

arranged in time sequence

Here are some Bucky Quotes (note: he made it up and I will release every email when things are safe)

"Even if there is a real attack, it is not easy to discern given his approach" (they were in possession of video of it since before this comment)

"They don't dive into your slack, you come to theirs, if and when you're invited" (referring to amulet)

"You're compromising the core security program that serves all chains" (this is the same security program that did not fix the ICA issue on the hub (I reported) and the same security program that did not fix banana king (reported at hacker one by felix and reported direclty to teams by myself)

"The reports that have been submitted are incomprehensible and laden with threatening language"

"Its like we have to deal with a hysterical child every few months. Are we trying to run a serious and professional organization or is this kindergarten?" (I've clearly found what I claim to have found)

"At least one of the thirty emails he sent seems to have some threatening language"

"I don't think I meant to make some serious allegation" (it'd be a felony to make threats pursuant to something like this, @ebuchman accused me of a felony and I take that seriously)

To ensure that there's no misunderstanding, I continue to request that @ebuchman please post any threatening language he feels I've used here. Thing is he later recanted all claim that there was threatening language and I just want some safety in the sense of not having felony accusations lobbed at me by members of an organization that includes threats in its security policy.

I've also been encouraged by a friend and mentor, @zmanian to fully ignore the machinations of the foundation and proceed, so that's what I'm going to do.

I'm also going to leave this PR open, because I feel that informal is in flagrant violation of the hub's governance, and that they are enhancing danger in cosmos by not working directly with security reporters, and I'm referring to more than myself.

Please know @jessica0f0116 -- that I am not nearly as well resourced as the Informal or the Interchain foundation.

I'm now going to work entirely on fixes, I've spoken my bit ad nauseam.

Copy link
Member

@jackzampolin jackzampolin left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We should close this PR in favor of #2820

Copy link
Contributor

@mpoke mpoke left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Rejecting in favor of #2820

@mpoke
Copy link
Contributor

mpoke commented Nov 17, 2023

Closing in favor of #2820

@mpoke mpoke closed this Nov 17, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants