Security response team

I think we need to form a security response team to be contacted for responsible disclosure. We could setup a shared email account and share a PGP keypair which we each sign with our own keys.

Tom Scott Mon 25 Feb 2013 7:37PM
Who owns diasporaproject.org anyway?

Jonne Haß Mon 25 Feb 2013 8:50PM
whois diasporaproject.org
gonna tell you. Somewhat.

goob Tue 26 Feb 2013 11:17AM
Max must know this person, or at least how to get in contact with them, otherwise they wouldn't have pointed diasporafoundation.org to his site in the first place - surely?

goob Tue 26 Feb 2013 11:17AM
Sorry, Maxwell, not Max - didn't mean to shorten his name.
fabianrbz Wed 27 Feb 2013 12:33AM
Count me in!

Ivan Gabriel Morén Sat 30 Mar 2013 11:53PM
A good, simple, secure and free mail, I think this one could do it:
They have both email and mailing lists. There are two ways to get an account, either by writing them a request and telling them who we are and why we want it, or by using invitation codes, and as both I and Paul do already have accounts for personal purposes we could generate invitation codes.
What do you say?

Jonne Haß Fri 2 Aug 2013 9:51PM
We now got full control over diasporafoundation.org, including a mail server listening to it, run by @dennisschubert. It's time to make security@diasporafoundation.org reality. I'm going to generate and publish a PGP key for it, anybody who wants to be in the team can contact me and I'll share the key with you, unless somebody knows a better method to get PGP working on that address.

goob Sat 3 Aug 2013 9:43AM
I've not heard about security@diasporafoundation.org before, Jonne. What is it intended to be? I'd like to know to see if it's something I could be a part of.

Jonne Haß Sat 3 Aug 2013 5:47PM
It's a method/address to responsibly, that is not in public, disclose serious security issues in Diaspora. Listening to it is the security response team (only me currently, heh...) to judge and handle the disclosed issues.

goob Sat 3 Aug 2013 6:33PM
Thanks. I saw from your discussion on Github that it's an email address for this purpose. I wasn't sure whether it was something else. A very good idea, but not something I can usefully be part of, I'm afraid.
Jonne Haß · Mon 25 Feb 2013 10:54AM
We still have no sign of life from the domain owner. That's basically why I'm asking.