Skip to content

Expand threat model documentation #20

@Slymeofthemonth

Description

@Slymeofthemonth

The threat model doc (docs/threat-model-and-design-rationale.md) needs additional entries for:

  • Unauthenticated WS/relay transport (MITM, impersonation)
  • Policy server compromise scenarios
  • Presignature pool attacks (exhaustion, tampering)
  • DoS on signing ceremonies
  • Key share encryption at rest threat analysis
  • Mark TEE mode as '(planned)' not current
  • Clarify key rotation requires full re-keygen + fund transfer

Ref: PR #14 CodeRabbit review

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions