Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Secure servers for software development and Tribler bootstrapping #5183

Open
synctext opened this issue Mar 6, 2020 · 0 comments
Open

Secure servers for software development and Tribler bootstrapping #5183

synctext opened this issue Mar 6, 2020 · 0 comments

Comments

@synctext
Copy link
Member

synctext commented Mar 6, 2020

By 2022 or beyond we need to focus on operational security of ourselves and our users.

Our testing servers, Github accounts (e.g. 2-factor for everybody), and users might be compromised by a determined adversary. Our users are vulnerable during the startup phase. We implemented the download of 25MByte of initial Trustchain data. In the 2022+ future we should consider upgrading our core infrastructure to be trustworthy. Leading CPU manufacturers have been know to create critical bugs and cripple user security for business interests. Alternative trustless infrastructure marketing blurb:

Talos™ II drives the state of the art of secure computing forward. Talos™ II gives you — and only
you — full control of your machine's security. Rest assured knowing that only your authorized
software and firmware are running via POWER9's secure boot features. Don't trust us? Look at the
secure boot sources yourself — and modify them as you wish. That's the power of Talos™ II.
In an industry first, Talos™ II ships with fully open and auditable BMC firmware, based on the 
Open BMC project. Gone are the days when you had to carefully isolate the buggy, insecure BMC
port from threats at the firewall level. With Talos™ II, the BMC is just another Linux system
that can be maintained as part of normal workflow. Find a bug or vulnerability? No problem; 
just patch, recompile, and install.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
No open projects
Development

No branches or pull requests

2 participants