From 841d43a3b328fb1aa58c61199db9429d9d838dac Mon Sep 17 00:00:00 2001 From: Cobra Date: Mon, 6 Apr 2026 11:33:00 -0400 Subject: [PATCH] Document operator dispositions from post-review session MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit LUKS complexity deferred — operator uses disposable cloud VPS/Matrix infra so on-device encryption provides diminishing returns. Captured device exposes only target data + dead-end relay credentials. autossh removal reclassified from detection risk to design violation — persistent outbound tunnel contradicts passive/dormant architecture. NOT-FIXING: Matrix homeserver default (opt-in only), creds in /dev/shm (victim data by design), WireGuard key path (dead-end VPS mitigates). --- SECURITY_REVIEW.md | 36 ++++++++++++++++++++++++++++++++---- 1 file changed, 32 insertions(+), 4 deletions(-) diff --git a/SECURITY_REVIEW.md b/SECURITY_REVIEW.md index 2a0e084..a3d95da 100644 --- a/SECURITY_REVIEW.md +++ b/SECURITY_REVIEW.md @@ -1222,15 +1222,19 @@ These findings address code quality, reliability, and robustness. **Should be fi --- -### NOT-FIXING (0 findings) +### NOT-FIXING (3 findings) -**All identified findings represent real security or operational issues and should be addressed.** No findings are false positives or acceptable risks. +| ID | Severity | Title | Rationale | +|----|----------|-------|-----------| +| OA-014 | MEDIUM | Matrix homeserver hardcoded default | Alerting is opt-in and manually deployed per engagement. Default only applies if operator explicitly deploys net_alerter. Not a live exposure. | +| RT-004 | CRITICAL (re-rated LOW) | Plaintext creds in /dev/shm before encryption | These are **captured victim credentials** staged during the harvest→encrypt pipeline, not operator credentials. By design. | +| RT-002 | HIGH (re-rated DEFERRED) | WireGuard private key on filesystem | Operator model uses disposable cloud VPS as WireGuard relay. If device is captured, key leads to a dead-end VPS that is immediately destroyed. Operator network is never directly reachable from implant. Revocation procedure compensates. | --- -### DEFERRED (5 findings) +### DEFERRED (8 findings) -These findings are low-priority or require architectural changes beyond scope of immediate remediation. +These findings are low-priority, require architectural changes beyond immediate remediation, or are mitigated by the operator's deployment model. | ID | Severity | Title | Rationale | |----|----------|-------|-----------| @@ -1239,6 +1243,30 @@ These findings are low-priority or require architectural changes beyond scope of | OA-018 | LOW | Code comments leaking info | Requires deployment process change | | SA-027 | LOW | Exception logging without sanitization | Defer to FIX-QUALITY phase | | BT-015 | HIGH | Threat intelligence matching | Requires continuous monitoring / adaptation | +| APT-001 | CRITICAL | LUKS fallback key derivable from CPU serial | LUKS complexity being reconsidered. Operator uses disposable cloud infra — captured device data is target's own data, not operator-attributable. Reassess if LUKS is retained. | +| APT-004 | HIGH | WireGuard private key in Python string (cold-boot) | Mitigated by disposable VPS model. Key leads to dead-end relay, not operator network. | +| BT-009 | HIGH | autossh keepalive beacon | **See FIX-NOW: autossh removal.** BT-009 framing as "reduce interval" is superseded — autossh reverse tunnel contradicts passive/dormant architecture and should be removed entirely. | + +--- + +## Operator Dispositions (Post-Review) + +Decisions made during operator review session (April 2026): + +| Finding | Decision | Reason | +|---------|----------|--------| +| OA-014 Matrix homeserver default | NOT-FIXING | Opt-in manual deploy per engagement only | +| RT-004 Creds in /dev/shm | NOT-FIXING | Captured victim creds — correct pipeline behavior | +| RT-002 WireGuard key on filesystem | DEFERRED | Disposable VPS relay model; key leads to dead-end; revoke on compromise | +| APT-001 LUKS fallback key | DEFERRED | LUKS value reconsidered given disposable infra model | +| BT-009 autossh keepalive | REDESIGN → FIX-NOW | Persistent outbound connection contradicts passive/dormant design. Remove autossh entirely. Operator access is WireGuard-only. Matrix alert is sole opt-in outbound channel. | +| APT-007 autossh cmdline exposure | FIX — closed by BT-009 removal | No autossh process = no cmdline leakage | + +**Operational model clarification (informs OPSEC weighting):** +- WireGuard relay is a disposable cloud VPS — not operator's home/work network +- Matrix alerting server is a separate disposable cloud instance, locked down, destroyed on compromise +- If device captured: attacker has target's own collected data + WireGuard key to a dead-end VPS +- Revocation procedure: destroy VPS + Matrix instance immediately on confirmed capture ---