Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Document copy & paste and log export via tagged VMs #33

Open
eloquence opened this issue Apr 17, 2020 · 0 comments
Open

Document copy & paste and log export via tagged VMs #33

eloquence opened this issue Apr 17, 2020 · 0 comments

Comments

@eloquence
Copy link
Member

freedomofpress/securedrop-workstation#533 implements an approach to permit copy & paste and log export via tagged VMs. This is intended to help us gain insights during the pilot about what changes to the default VM configuration and RPC policies may be ultimately desirable.

Because no VMs have the sd-send-clipboard, sd-receive-clipboard or sd-receive-logs tags by default, we need to document our initial recommendations for the use of these tags. For now, my thinking is:

  • Add a recommendation to the install docs to add sd-send-clipboard to the existing vault VM if and only if the organization intends to use KeePassX in vault to store SecureDrop login credentials.
  • Add a recommendation to the install docs to add sd-receive-logs to work (or another similar VM) so that it can be used for sharing selected logs, after inspection and redaction in sd-log.
  • Add a section to the Admin Guide "Managing clipboard access" that goes into further detail about the use of the clipboard, the security risks (including opsec), and the process for whitelisting access for select VMs.
  • Update the FAQ entry about clipboard access accordingly.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant