Skip to content

Conversation

@sukima
Copy link
Member

@sukima sukima commented Apr 30, 2018

Closes #73

Using the security.txt draft spec this PR creates a signed security.txt file along with an associated acknowledgements and privacy policy pages.

The public key was generated using GnuPG and its associated private key was saved to Keybase.io in the newhavenio.admins team where only a select few members have access and that membership list can be adjusted over time.

The acknowledgements, privacy policy, and PGP key are optional which means they can be removed. I split each out so we can drop the commits if we wish (sans the security.txt which is an easy amend). I included all the features as a kick-start for either inclusion/refinement or discussion.

  • Remove acknowledgement page
  • Have sign-off on a Privacy Policy page
  • Conciser removing the optional GPG signature and public key

sukima added 4 commits April 30, 2018 13:54
This is the signing key for security.txt and the key that researchers
can encrypt to if they feel the need to keep communication secret.

The private (secret) is stored in Keybase.io to the newhavenio.admins
team where only a select few members have access and that membership
list can be adjusted over time.
This is based on the template provided by https://securitytxt.org
This is an optional idea but highly encouraged by the specifications.
I copied the policy I have on my static blog site
https://tritarget.org/#Privacy%20Policy
We would like to thank the following for their generous contributions to this
site:

* [@sukima](https://tritarget.org/)
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

pats himself on the back, eh?

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Well, TBH a name there looked better then

* TODO: Put something here.

But yeah. shameless self promotion. 😊

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Acknowledgement page is optional and in this simple case is likely overkill. With the possibility of PR #101 this also becomes redundant and more maintenance overhead. I think I should reevaluate this PR.

@sukima sukima changed the title Add security.txt and related fiels Add security.txt and related files Apr 30, 2018
title: Privacy Policy
---

If you require any more information or have any questions about our privacy policy, please feel free to [contact us by email][ContactInfo].
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@jnimety @lourinaldi @ZachBeta we should review this text

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

If this copy is used there should be a section concerning the Meetup.com API and our use of it.

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Agreed that we should review the text. @sukima, I'm guessing this is a template? What's the source?

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@danbernier I copy/pasta it from my personal static blog site. I think I google searched for some template. But it looks like I didn't log the original source when I made mine.

The content here was intended to be a placeholder or simply to get things started.

@treznick treznick changed the base branch from master to develop May 7, 2018 01:55
@sukima
Copy link
Member Author

sukima commented May 17, 2018

Is the GPG signature and public key needed? is it worth having?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants