Skip to content

security(auth): owner decisions on the sign-in lock and the audit address hash (D-064, D-065) #879

Description

@alex-dembele

Problem

Two limits accepted in #688 (PR #874) need an owner decision before any code, because each one touches auth or crypto design (CLAUDE.md, escalation rules). They are recorded as D-064 and D-065 in docs/DECISIONS.md.

  1. Anyone can keep an address locked (D-064). After 10 failed sign-ins from any source, an address is locked for 15 min. Anyone who knows an address can re-lock it every 15 minutes, indefinitely, without knowing the password. The owner's only way out is a password reset. Same trade-off as the MFA lock (security(auth): MFA challenge codes can be guessed without limit — no attempt counter, no rate limit #689).
  2. Audit hash can be reversed (D-065). Failed sign-ins are audited with email_sha256=<hex>, an unsalted SHA-256. Anyone who can read the audit trail and holds a list of candidate addresses can recover which address was targeted. The same hash keys the password-reset limiter (domain.HashEmailForReset).

Acceptance criteria

Set once the owner decides; until then this issue is status:blocked.

  1. D-064 is decided and the chosen option is implemented, or recorded as accepted with no code.
  2. D-065 is decided and the chosen option is implemented, or recorded as accepted with no code.

Definition of Done

  • Both decisions moved to Resolved in docs/DECISIONS.md.
  • Any resulting code: tests + gates green, PR with Closes.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:backendGo, /internal, /pkgarea:securityCybersecurity and threat intelligencepriority:P2Normalpriority:P2-mediumNormal milestone workstatus:blockedWaiting on a decision or another issuetier:0-trustTrust: security, isolation, evidence integritytype:securitySecurity defect or hardening

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions