Skip to content

Discoverable list of security tradeoffs #7900

Description

@jskinne3

An experiment

Hypothesis: if we list the security assumptions and tradoffs that cause the most confusion in bug reports, we will get fewer false positive bug reports from both human and LLM bughunters. We'd detail both the design decision ("all journalists can see all submissions") and the consequences ("we do not validate reply_uuid belongs to source_uuid").

We could list them in:

The plan:

  • First, list top 5-10 of our hottest false positives
  • Put the list into Bugcrowd ineligible submissions
  • Determine where (and if?) to transfer a similar list (maybe with more details) to the codebase
  • Put the list in place; include links to related material like github issues and code
  • See if false positive reports go down, developer comprehension goes up

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

Status
Blocked or Waiting

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions