TAP 19: should discuss privacy
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 32/100
- Issue type
- Documentation
- Clarity
- Mostly clear
- Activity status
- Stale
- Domain
- documentation, security
Research direction
Read TAP 19 first, then review the passim and fwupd privacy context described in this issue. Document how content-addressable storage can reveal downloads to untrusted participants, and compare that exposure with traditional TUF; the TAP is done when these privacy implications are clearly discussed.
Written by the indexing model from the issue text.
Description
While I was readin up on passim (a mDNS based content addressable storage) I noticed that their main use case fwupd does not use passim for artifact downloads because of privacy reasons: They don't want the other download "source" (which is potentially untrusted) to know which firmware files get downloaded.
I think TAP 19 should discuss the privacy implications as well: I think they exist in some form for all content addressable storage where the participants are not completely trusted (in comparison to traditional TUF where the privacy leak happens only to the relatively more trusted TUF artifact repository).
- Dominant language
- No language data
- Stars
- 37
- Forks
- 23
- PR merge metrics
- No merged PRs in 30d
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from theupdateframework/taps
-
Difficulty 5/5 Over a week Newbie friendliness 42/100
theupdateframework/taps#194 ·
-
Difficulty 5/5 Over a week Newbie friendliness 20/100
theupdateframework/taps#191 · 8 comments ·
-
Difficulty 5/5 Over a week Newbie friendliness 25/100
theupdateframework/taps#190 · 19 comments · 1 reaction ·
-
Difficulty 5/5 Over a week Newbie friendliness 25/100
theupdateframework/taps#177 · 1 comment · 3 reactions ·
-
Difficulty 5/5 Over a week Newbie friendliness 25/100
theupdateframework/taps#171 · 1 reaction ·
All issues in theupdateframework/taps
Similar issues
-
sync-en
Difficulty 1/5 1-3 hours Newbie friendliness 88/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
agilepathway/label-checker#640 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
BasedHardware/omi#15662 · 1 comment ·
-
documentation help wanted
Difficulty 2/5 1-3 hours Newbie friendliness 90/100
-
Difficulty 1/5 1-3 hours Newbie friendliness 88/100