Skip to content

Tighten v1 security invariants and define the trusted-computer boundary #4

Description

@BenWestgate

The v1 security documentation needs one literal, consistent trusted-computer and secret-output contract.

Required contract:

  • define a trusted computer operationally as a machine under the operator's exclusive control, not known or suspected to be compromised, with the OS/Python environment/codex32/bitcoin-cli/Bitcoin Core and relevant configuration trusted for the operation;
  • distinguish intentional secret-emitting commands from accidental disclosure so invariant 6 is literally true;
  • warn that shell command text can be retained even when prompted or redirected stdin keeps secrets out of argv;
  • keep SECURITY.md, the security model/invariants, user guidance, and CLI help consistent.

Implemented in focused PR #59. The final refreshed head ede98a8 is mergeable, has resolved review threads, passed exact-head Python-package run 643 and Bitcoin Core wallet-fixture run 30, and has a current-head Codex release-gate ACK. The refreshed wording is reconciled with #23 and the #57/#80/#81 restore contract.

Keep this issue open through human integration of #59; no automated/code-review gap remains.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: securitySecurity invariants, hardening, and security-sensitive boundaries.documentationImprovements or additions to documentationgate: adversarial reviewResolve, merge, or explicitly defer before the next full adversarial review.

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions