Replies: 3 comments 4 replies
-
I am definitely interested, and at least one other meson developer has expressed interest. |
Beta Was this translation helpful? Give feedback.
-
Excellent! Please collect the number of tokens you need for the whole project and if you have preferences on which type you want. I will also need personal email addresses of the people who will get them (so that we can send the code used to "buy" one). |
Beta Was this translation helpful? Give feedback.
-
We had a chat and decided that I'd gather all the ones who want one and add their data here. So here is the official list, which I will update as people let me know what they want: TitansYubikeysEmail sent, so this is the final list. |
Beta Was this translation helpful? Give feedback.
-
Hi! I work with the Developer Best Practices Working Group of the
Linux Foundation's Open Source Security Foundation (OpenSSF)
https://github.com/ossf/wg-best-practices-os-developers "Great
Multi-Factor Authentication (MFA) Distribution Project"
https://github.com/ossf/great-mfa-project.
We'd like to give your project free MFA hardware tokens from
Google and GitHub, for use by your maintainers. We'd especially
like to give them to any of your maintainers who aren't already
using any. Our goal is to help improve the security of open source
software (OSS)/Free Software projects. For example, these tokens
can counter attacks that release source code updates and/or packages
using stolen passwords.
By 2021-12-20 and preferably much sooner, please let me know:
(this email must not go to the public, as these are use-once
codes that can be used to get the tokens)
We would send you coupon codes and validation codes to the private
email address. You would then distribute those codes to the
maintainers you choose. The recipients would use the coupon codes
and validation codes to "buy" the tokens from the Google Store
and/or GitHub Shop, who would ship the tokens directly to recipients.
These codes are use-once, so make sure you can keep the codes private
until they're used by the intended person.
Important: The Google coupon codes must be used by 2021-12-31
on the Google Store or they expire.
How can you trust us? You don't need to. You would get the MFA
tokens from Google and GitHub; we're simply offering codes to make
them no-cost. We'll provide some documentation on how to use them,
but you don't need to use our documents.
To qualify, each token recipient must:
project, or to another OSS project that this project depends on
(the dependency may be indirect).
We'd like recipients to use MFA tokens from then on, but at least try.
We also need each project that receives coupon codes and/or validation codes
to tell us these numbers (preferably within 30 days of getting the codes):
From both?
received tokens from just Google? From just GitHub? From both?
We ask for this information so we can tell others some simple
measures of success. We don't need nor want the names of any
individuals participating. It's fine to ask the people who got the
codes for that information and provide a best-effort summary.
The MFA tokens are shipped from the US. They can be shipped
internationally, but there are various limitations on where each
can be shipped.
In particular, we can't ship somewhere if that is forbidden
(sanctioned) under US law. So at this time we are unable to ship
to individuals in China, Afghanistan, Russia, Ukraine, North Korea,
Iran, Sudan, and Syria. Sorry about that. See the Google and
GitHub sites for more shipping information. More sanction information
is available at
https://home.treasury.gov/policy-issues/financial-sanctions/sanctions-programs-and-country-information.
For more information including how-tos and other setup information
can be found at the "Great Multi-Factor Authentication (MFA)
Distribution Project" site: https://github.com/ossf/great-mfa-project.
Beta Was this translation helpful? Give feedback.
All reactions