Hardware, platform and safety / Security and privacy
What should owners check about “Security model and threat model”, in particular regarding external review not done?
Designed in a document, no code yet C0197
A written security model exists in the repository: assets, attackers, eight rules (true removal, signed everything, local authority for offline use only, online features decided by the host, no hidden doors, staging discipline, break-in tests, an honest limit) and a table of what is built and what is not. A full threat model, an external security review and the host design are planned. Plan for: external review not done; host not built; a person who holds the code can attack the code. It is designed in a document and no code exists.
How to read this
The tag above says how real the answer is. Answers describe the plan in the repository and design documents. No app is released. Where an answer touches tax or law, treat it as a theme to verify with a qualified local adviser.
More in Security and privacy
- Why does “Software supply chain” matter for a small business, considering dependency vulnerabilities?
- What should I plan for with “True removal of unselected elements”, with a focus on a removed element's data is a separate choice?
- Why does “No hidden doors” matter for a small business, especially around applies to the code that exists?
- See it in context with the whole topic
- Search all answers