From eb4668408ceac440972213053ab0d97f6fa7ae89 Mon Sep 17 00:00:00 2001 From: stefan Date: Mon, 23 Feb 2026 18:53:35 +0100 Subject: SLSA models added Signed-off-by: stefan --- .../GnuPG-WoT-Download/201-ThreatModel-SLSA4-ReproducibleBuilds.svg | 1 + 1 file changed, 1 insertion(+) create mode 100644 PlantUML-ModelingTrust/GnuPG-WoT-Download/201-ThreatModel-SLSA4-ReproducibleBuilds.svg (limited to 'PlantUML-ModelingTrust/GnuPG-WoT-Download/201-ThreatModel-SLSA4-ReproducibleBuilds.svg') diff --git a/PlantUML-ModelingTrust/GnuPG-WoT-Download/201-ThreatModel-SLSA4-ReproducibleBuilds.svg b/PlantUML-ModelingTrust/GnuPG-WoT-Download/201-ThreatModel-SLSA4-ReproducibleBuilds.svg new file mode 100644 index 0000000..231e779 --- /dev/null +++ b/PlantUML-ModelingTrust/GnuPG-WoT-Download/201-ThreatModel-SLSA4-ReproducibleBuilds.svg @@ -0,0 +1 @@ +Threat Model - Reproducible Builds according to SLSA Level 4using independent GnuPG signatures and keysas well as Reproducible Builds according to SLSA Level 4corresponding to the Tor Browser release process, as well as NixOS, Debian and NetBSD2026-02-23 06:52MaintainerIndependent build pipelines(at least 2)Download artefactsOperational environment(of the downloader)Source Code(in Git)Git Release Tag(GnuPG-signed)Pipe APipe BArtefact A(Checksum)Artefact B(Checksum)Known public signing keys(obtained from at least2 independent trust paths)Rebuild pipeline(Reproducible)Verification policy(organisational measurefrom BSI TR)Downloader(Verifier)Internet(Insecure)NTP Server 1NTP Server 2Attacker(Insider / External)Keyserver 1Keyserver 2Git Transparency Log(tamper-hardened)Distributed ledger withMerkle Tree records(Blockchain)TimeTimeretrievesretrievesChecksumChecksumChecksumChecksumcompromisescontrolscompromises private keyACCEPT / REJECTThreat Model - Reproducible Builds according to SLSA Level 4Advantages:Consistency between source code and binaries through Reproducible BuildsNo single trust anchor -> at least 2 independent buildersSubsequent manipulation detectable through checksums in the Git Transparency LogInsider attacks made more difficult through multiple signaturesKey misuse detectable through checksums in the Git Transparency Log and temporal correlation via timestampsEach box is a trust boarder \ No newline at end of file -- cgit v1.2.3