Skip to content

security: external review of the verification core + hand-rolled codecs (funded audit) #75

Description

@luisgf

Value/Effort: high / M (mostly organizational). docs/threat-model.md was written "for external-audit readiness" — cash that cheque. A solo-maintained crypto library earns institutional trust through third-party review: scope the audit to the fail-closed pipeline properties, the three proof families, and the hand-rolled parsers that face attacker-controlled bytes (CBOR, JCS, multibase, bitstring, the TSL XML path).

Scope: prepare the audit pack (threat model, invariants, fuzz corpora, the adversarial-review history); pursue EU open-source funding routes (NGI/NLnet, Sovereign Tech Fund — openvc's EUDI relevance is the pitch); publish findings + fixes. Pairs with the W3C/OIDF conformance evidence from the medium-term milestone as the credibility story.

Metadata

Metadata

Assignees

No one assigned

    Labels

    hardeningAssurance: fuzzing, negative corpus, threat modelsecuritySecurity / hardening

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions