Security Working Group Minutes

February 5, 2025

Participants: Dan Janowski, @varnerac, Lee Barney, @maennchen, @voltone, Marc Nickert, Michael Lubas, Paul Swartz, Bas Wegh, @kiko

Compliance updates

CNA (CVE Numbering Authority)

  • Still pending a response from MITRE
    • Proposed meeting slots in February approaching

CISA Self Attestation and NIST SSDF

  • To be discussed in call with NIST
    • Some uncertainty about whether EEF can do this on behalf of projects

OpenChain

  • Erlang/OTP certified (see @kiko’s announcement)
  • Working on Elixir and Gleam
    • Source SBOM
    • Policies

Source SBoM of OTP

  • Contributions to OSS Review Toolkit accepted
  • Source SBOM will be published with OTP releases starting with OTP 28
  • Working on splitting SBOM by application

Application for Supply Chain Funding

  • Trying to obtain funding for ongoing supply chain work
  • Next step: align with documented package manager best-practices
    • Get hex.pm involved, as well as build tools (Mix, Rebar3)

Erlang distribution protocol hardening

  • Picking up discussion started in Slack
  • Initial idea (Dan): make it easier to secure with TLS out of the box
    • Issuing certificates
    • Injecting kernel parameters
  • Broader use-cases (Lee): connecting (possibly transient) nodes across the Internet
    • Instead of having to go through e.g. HTTPS
    • Large clusters, frequent membership changes, unreliable nodes
    • Security aspects just one part of it
  • Invited Lee to present his work to the group in the future
  • Offered Dan support with first round of research into possible approaches

Other updates

PenTest Sample App

  • Michael just finished pen-testing Oban Pro, might be interested
  • Need to start collecting requirements for the app’s scope
    • Take it to Slack or Notion (see below)

WG collaboration tooling

  • We have access to Notion, with non-profit discounts
    • Read-only access is free, must pay per write-enabled seat
    • Currently being used by @maennchen for broader EEF work
  • Open it up a bit, start linking from Slack and meeting notes
    • Create a landing page for the WG
    • Keep licensed seats at a minimum

Next meeting

Wed 5 March 2025 at 16:00 CET / 15:00 GMT / 10am EST / 7am PST / 0:00 (Thu) JST

7 Likes