proposal: #security:f-droid.org E2EE Matrix room
We need a secure channel to coordinate on security topics. Matrix with E2EE gives us a nice way that many of us are already using. I propose making a dedicated Matrix room on our server to do this. Here's the terms:
- Discussion must be limited to specific security-related details that must be kept secret, like responsible disclosure coordination or dealing with active attacks.
- Room called
#security:f-droid.org
- E2EE on by default and required
- Only accounts with verified devices allowed in
- Must be a core contributor listed on https://gitlab.com/fdroid to be eligeable.
- Must have a specific need to have access, e.g. leading up responsible disclosure coordination for apps or running security-sensitive servers for F-Droid.
- As much as possible, discussions should be made public ("declassified") once it is safe to do so (e.g. responsible disclosure discussions once the CVE and fix is released).
- Information declassified from
#security:f-droid.org
must only be made public under the Chatham House Rule: "neither the identity nor the affiliation of the speaker(s), nor that of any other participant, may be revealed". - Did I forget anything?
To mark your support, please put a
The open question is: who should be included? Please propose people in the comments. @All