From 2993aae60e019804e249de3f56e48eca365723df Mon Sep 17 00:00:00 2001 From: stefan Date: Tue, 24 Feb 2026 20:36:44 +0100 Subject: Risk/Security Overlay im Business/Motivation Layer angefangen --- .../202-ThreatModel-SLSA4-ReproducibleBuilds-TrustAnchor.svg | 1 + 1 file changed, 1 insertion(+) create mode 100644 PlantUML-ModelingTrust/GnuPG-WoT-Download/202-ThreatModel-SLSA4-ReproducibleBuilds-TrustAnchor.svg (limited to 'PlantUML-ModelingTrust/GnuPG-WoT-Download/202-ThreatModel-SLSA4-ReproducibleBuilds-TrustAnchor.svg') diff --git a/PlantUML-ModelingTrust/GnuPG-WoT-Download/202-ThreatModel-SLSA4-ReproducibleBuilds-TrustAnchor.svg b/PlantUML-ModelingTrust/GnuPG-WoT-Download/202-ThreatModel-SLSA4-ReproducibleBuilds-TrustAnchor.svg new file mode 100644 index 0000000..a1071dc --- /dev/null +++ b/PlantUML-ModelingTrust/GnuPG-WoT-Download/202-ThreatModel-SLSA4-ReproducibleBuilds-TrustAnchor.svg @@ -0,0 +1 @@ +Threat Model - Reproducible Builds according to SLSA Level 4using independent GnuPG signatures and keysas well as Reproducible Builds according to SLSA Level 4corresponding to the Tor Browser release process, as well as NixOS, Debian and NetBSD2026-02-24 12:20MaintainerIndependent build pipelines(at least 2)Download artefactsOperational environment(of the downloader)Source Code(in Git)   Git Release Tag(GnuPG-signed)   Pipe A  b1Pipe B  b2Artefact A(Checksum)Artefact B(Checksum)Known public signing keys(obtained from at least 2 independent trust paths)Rebuild pipeline(Reproducible)Verification policy (organisational measure from BSI TR)Downloader(Verifier)Internet(Insecure)NTP Server 1NTP Server 2Attacker(Insider / External)Keyserver 1Keyserver 2combined TrustGit Transparency Log(tamper-hardened)  Distributed ledger with Merkle Tree records (Blockchain)  combines TAcombines TATimeTimeretrievesretrievesChecksumChecksumChecksumChecksumcompromisescontrolscompromises private keyACCEPT / REJECTThreat Model - Reproducible Builds according to SLSA Level 4Advantages:Consistency between source code and binaries through Reproducible BuildsNo single trust anchor -> at least 2 independent buildersSubsequent manipulation detectable through checksums in the Git Transparency LogInsider attacks made more difficult through multiple signaturesKey misuse detectable through checksums in the Git Transparency Log and temporal correlation via timestampsEach box is a trust boarder \ No newline at end of file -- cgit v1.2.3