documentationhelp wantedsecurity
Repository metrics
- Stars
- (137 stars)
- PR merge metrics
- (PR metrics pending)
Description
Before moving closer to production readiness, we need to perform a comprehensive security audit of the entire codebase to identify potential vulnerabilities, misconfigurations, or unsafe patterns.
This is especially important given that:
- The application handles cryptographic operations (e.g. Diffie-Hellman, PSK generation),
- There is WebSocket communication and encryption,
- Nodes can interact over untrusted networks,
- There is potential for user-generated content and decentralized identity.
Audit Scope Should Include:
- Cryptography:
- Validate usage of secure algorithms and key exchange.
- Ensure no use of weak or deprecated crypto primitives.
- Memory & Binary Security: check anti-debugging, hardening flags, stripping, Go build flags.
- Network & Transport: validate handshake mechanisms, replay protection, peer authentication.
- Identity & Secrets: ensure proper handling and storage of private keys, salts, and tokens.
- Input Validation: sanitize and validate incoming requests/messages across interfaces.
- P2P Discovery & Trust: ensure nodes can’t spoof others or bypass trust mechanisms.
- Optional: Fuzzing high-risk entry points (e.g. WebSocket handlers, import routines).
Result:
- List of discovered issues with severity levels.
- Recommendations for fixing or mitigating each issue.
- CI integration suggestions (e.g. static analysis tools, linters, SAST).
Contributors with experience in security, cryptography, or Go auditing are welcome to join or advise.