Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Brand, NameHub docs should include global naming security considerations: phishing etc. #10702

Open
dckc opened this issue Dec 16, 2024 · 0 comments
Labels
cosmic-swingset package: cosmic-swingset devex developer experience documentation Improvements or additions to documentation enhancement New feature or request ERTP package: ERTP security

Comments

@dckc
Copy link
Member

dckc commented Dec 16, 2024

What is the Problem Being Solved?

Brand reference docs don't say why we use unforgeable objects rather than contract addresses (large ~random numbers) nor (only) cosmos denom strings for identification.

NameHub doesn't say how it addresses phishing risks.
nor Board.

Name Service docs (board, agoricNames, namesByAddress) are likewise silent.

endo reference docs don't include the petname daemon.
I don't see anything relevant in the endo daemon sources

Description of the Design

@erights is a co-author on...

That seems to cite Zook's triangle and such.

Borrow material from there.

A search for petname among our youtube videos also turns up a number of hits.

The AllegedName glossary entry hints at the issues.

Security Considerations

yes

Scaling Considerations

no

Test Plan

tests and/or working examples to show the risks in tangible fashion would be ideal

Upgrade Considerations

not much?

cc @kriskowal @michaelfig @amessbee @heavypackets

@dckc dckc added documentation Improvements or additions to documentation enhancement New feature or request ERTP package: ERTP cosmic-swingset package: cosmic-swingset security devex developer experience labels Dec 16, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
cosmic-swingset package: cosmic-swingset devex developer experience documentation Improvements or additions to documentation enhancement New feature or request ERTP package: ERTP security
Projects
None yet
Development

No branches or pull requests

1 participant