# Proposal: Security Working Group

**URL:** <https://internals.rust-lang.org/t/proposal-security-working-group/8282>\
**Category:** Uncategorized\
**Created:** [August 23, 2018, 7:41pm UTC](https://internals.rust-lang.org/t/proposal-security-working-group/8282 "2018-08-23T19:41:16Z")\
**Posts on this page:** 20\
**Page:** 7

<div class="post-metadata">

**Author:** ![Centril](https://sea2.discourse-cdn.com/flex002/user_avatar/internals.rust-lang.org/centril/32/3334_2.png) [@Centril](https://internals.rust-lang.org/u/Centril)\
**Post date:** [September 21, 2018, 10:32pm UTC](https://internals.rust-lang.org/t/proposal-security-working-group/8282/121 "2018-09-21T22:32:39Z")

</div>

> [@Shnatsel](#):
>
> Join the effort of verifying the standard library using fuzzers and quickcheck at [https://github.com/blt/bughunt-rust](https://github.com/blt/bughunt-rust)

Don't forget:

> **[GitHub - proptest-rs/proptest: Hypothesis-like property testing for Rust](https://github.com/proptest-rs/proptest)**
>
> Hypothesis-like property testing for Rust. Contribute to proptest-rs/proptest development by creating an account on GitHub.

---

<div class="post-metadata">

**Author:** ![joshlf](https://sea2.discourse-cdn.com/flex002/user_avatar/internals.rust-lang.org/joshlf/32/3815_2.png) [@joshlf](https://internals.rust-lang.org/u/joshlf)\
**Post date:** [September 24, 2018, 7:08pm UTC](https://internals.rust-lang.org/t/proposal-security-working-group/8282/122 "2018-09-24T19:08:51Z")

</div>

OK, I’ve scheduled a meeting for tomorrow - Tuesday, Sept 25th - at 11:00 am - 12:00 pm PST (18:00 - 19:00 UTC).

You can join on [Google hangouts](https://meet.google.com/amj-yjmd-qfn) (you do not have to be logged in) or call by phone: +1 417-429-4644 (PIN: ‪213 570#‬).

As I mentioned in the previous comment, this meeting’s purpose will be to discuss what we want the focus of the WG to be. I’ll prioritize ideas that have been discussed in this thread, so if you have a new idea you’d like to discuss, please post it here so people can read it first.

See you all tomorrow!

---

<div class="post-metadata">

**Author:** ![stusmall](https://sea2.discourse-cdn.com/flex002/user_avatar/internals.rust-lang.org/stusmall/32/4607_2.png) [@stusmall](https://internals.rust-lang.org/u/stusmall)\
**Post date:** [September 24, 2018, 7:26pm UTC](https://internals.rust-lang.org/t/proposal-security-working-group/8282/123 "2018-09-24T19:26:58Z")

</div>

Thanks for getting something on the calendar. I’m looking forward to it.

Edit: The link doesn’t appear to work.

---

<div class="post-metadata">

**Author:** ![joshlf](https://sea2.discourse-cdn.com/flex002/user_avatar/internals.rust-lang.org/joshlf/32/3815_2.png) [@joshlf](https://internals.rust-lang.org/u/joshlf)\
**Post date:** [September 24, 2018, 8:07pm UTC](https://internals.rust-lang.org/t/proposal-security-working-group/8282/124 "2018-09-24T20:07:39Z")

</div>

Try now?

---

<div class="post-metadata">

**Author:** ![stusmall](https://sea2.discourse-cdn.com/flex002/user_avatar/internals.rust-lang.org/stusmall/32/4607_2.png) [@stusmall](https://internals.rust-lang.org/u/stusmall)\
**Post date:** [September 24, 2018, 8:18pm UTC](https://internals.rust-lang.org/t/proposal-security-working-group/8282/125 "2018-09-24T20:18:20Z")

</div>

That did it. Thank you.

---

<div class="post-metadata">

**Author:** ![snf](https://sea2.discourse-cdn.com/flex002/user_avatar/internals.rust-lang.org/snf/32/4698_2.png) [@snf](https://internals.rust-lang.org/u/snf)\
**Post date:** [September 25, 2018, 10:13pm UTC](https://internals.rust-lang.org/t/proposal-security-working-group/8282/126 "2018-09-25T22:13:59Z")

</div>

Anyone has notes from the meeting?, I couldn’t assist it this week.

---

<div class="post-metadata">

**Author:** ![stusmall](https://sea2.discourse-cdn.com/flex002/user_avatar/internals.rust-lang.org/stusmall/32/4607_2.png) [@stusmall](https://internals.rust-lang.org/u/stusmall)\
**Post date:** [September 25, 2018, 10:14pm UTC](https://internals.rust-lang.org/t/proposal-security-working-group/8282/127 "2018-09-25T22:14:54Z")

</div>

Joshua took detailed notes. I believe he said he will post them later.

---

<div class="post-metadata">

**Author:** ![joshlf](https://sea2.discourse-cdn.com/flex002/user_avatar/internals.rust-lang.org/joshlf/32/3815_2.png) [@joshlf](https://internals.rust-lang.org/u/joshlf)\
**Post date:** [September 25, 2018, 10:33pm UTC](https://internals.rust-lang.org/t/proposal-security-working-group/8282/128 "2018-09-25T22:33:53Z")

</div>

I wasn’t planning on posting the notes themselves since they are pretty noisy, but certainly the summary. I’m just waiting to figure some last things out so I can post all at once rather than a series of small posts. This thread is long enough as is 😛

---

<div class="post-metadata">

**Author:** ![ZerothLaw](https://sea2.discourse-cdn.com/flex002/user_avatar/internals.rust-lang.org/zerothlaw/32/4618_2.png) [@ZerothLaw](https://internals.rust-lang.org/u/ZerothLaw)\
**Post date:** [September 26, 2018, 3:22pm UTC](https://internals.rust-lang.org/t/proposal-security-working-group/8282/129 "2018-09-26T15:22:33Z")

</div>

Argh, apparently missed notification that there was going to be a meeting yesterday. Ah well, next time!

---

<div class="post-metadata">

**Author:** ![DrizztVD](https://sea2.discourse-cdn.com/flex002/user_avatar/internals.rust-lang.org/drizztvd/32/4521_2.png) [@DrizztVD](https://internals.rust-lang.org/u/DrizztVD)\
**Post date:** [October 11, 2018, 2:49pm UTC](https://internals.rust-lang.org/t/proposal-security-working-group/8282/130 "2018-10-11T14:49:11Z")

</div>

> [@joshlf](#):
>
> so I can post all at once rather than a series of small posts.

What's the status of the summary?

In other news, here is another great article about national cybersecurity:

> **[How the US Forced China to Quit Stealing—Using a Chinese Spy](https://www.wired.com/story/us-china-cybertheft-su-bin/)**
>
> For years, China has systematically looted American trade secrets. Here's the messy inside story of how DC got Beijing to clean up its act for a while.

---

<div class="post-metadata">

**Author:** ![joshlf](https://sea2.discourse-cdn.com/flex002/user_avatar/internals.rust-lang.org/joshlf/32/3815_2.png) [@joshlf](https://internals.rust-lang.org/u/joshlf)\
**Post date:** [October 11, 2018, 5:55pm UTC](https://internals.rust-lang.org/t/proposal-security-working-group/8282/131 "2018-10-11T17:55:24Z")

</div>

> [@DrizztVD](#):
>
> > so I can post all at once rather than a series of small posts.
> 
> What’s the status of the summary?

We just met with the core team yesterday, and we're waiting for them to make some decisions about administrative details. We should have more for you in the next day or so.

---

<div class="post-metadata">

**Author:** ![jethrogb](https://avatars.discourse-cdn.com/v4/letter/j/43a26b/32.png) [@jethrogb](https://internals.rust-lang.org/u/jethrogb)\
**Post date:** [October 11, 2018, 6:02pm UTC](https://internals.rust-lang.org/t/proposal-security-working-group/8282/132 "2018-10-11T18:02:09Z")

</div>

@joshlf At the very least you should be able to post the meeting notes for those who weren’t able to attend the meeting.

---

<div class="post-metadata">

**Author:** ![DrizztVD](https://sea2.discourse-cdn.com/flex002/user_avatar/internals.rust-lang.org/drizztvd/32/4521_2.png) [@DrizztVD](https://internals.rust-lang.org/u/DrizztVD)\
**Post date:** [October 11, 2018, 7:32pm UTC](https://internals.rust-lang.org/t/proposal-security-working-group/8282/133 "2018-10-11T19:32:30Z")

</div>

> [@joshlf](#):
>
> We just met with the core team yesterday, and we’re waiting for them to make some decisions about administrative details.

Cool. Glad to see it being official and all. As such matters should.

---

<div class="post-metadata">

**Author:** ![joshlf](https://sea2.discourse-cdn.com/flex002/user_avatar/internals.rust-lang.org/joshlf/32/3815_2.png) [@joshlf](https://internals.rust-lang.org/u/joshlf)\
**Post date:** [October 12, 2018, 5:35pm UTC](https://internals.rust-lang.org/t/proposal-security-working-group/8282/134 "2018-10-12T17:35:05Z")

</div>

OK, heard back from the core team. It’s on!

## Mission and Scope

The WG’s mission is to make it easy to write secure code in Rust. We have the following concrete goals:

1. Most tasks shouldn’t require dangerous features such as `unsafe`. This includes FFI.
2. Mistakes in security code should be easily caught.
3. It should be clear to programmers how to use security-sensitive APIs correctly.
4. Security-critical code which is relied on by Rust programmers should be bug free.

Here are some examples of some work that we might do in service of these goals. All of these examples are possibilities, but we aren’t guaranteeing that we’ll tackle any given work item, and the list isn’t exhaustive.

- _Most tasks shouldn’t require dangerous features such as `unsafe`. This includes FFI._
  - Identify common uses of `unsafe` or other dangerous features, and write crates/stdlib features/language features to provide the same functionality behind safe APIs

- _Mistakes in security code should be easily caught._
  - Write clippy lints for common security mistakes
  - Make sure it’s easy to integrate new static analysis tools into Rust

- _It should be clear to programmers how to use security-sensitive APIs correctly._
  - Contribute to documentation of security-sensitive APIs in crates/stdlib
  - Write guidelines on how to design security-sensitive APIs

- _Security-critical code which is relied on by Rust programmers should be bug free._
  - Encourage/participate in bug hunting in stdlib/crates
  - Take ownership of the [RustSec](https://github.com/RustSec) project

## Out of Scope

Cryptography will be explicitly outside of the scope of the WG. There is interest from some in starting a Cryptography Working Group, but that will be left for other efforts.

The following responsibilities were proposed at various times in the preceding discussion, but we decided not to take those on as responsibilities for the WG:

- Curating “approved” crates
  - Reasoning: It’s too early to get behind single solutions for many security problems, and important to leave room for more innovation and exploration. This may make sense in the future if there’s community consensus, but it doesn’t make sense now.

- Support for memory corruption mitigations (stack canaries, CFI, etc)
  - Reasoning: Our efforts are better spent on improving memory safety and its adoption, which makes these mitigations unnecessary.

- Fuzzing
  - Reasoning: There’s already a well-established fuzzing effort.

- Rust security book
  - Reasoning: It’s unclear what would go in here, and in any case, not high enough priority to focus on right now.

## Administrative

The WG will report to the core team.

## Naming

We want to make sure that people don’t mistakenly think that we’re in charge of things like triaging security issues (that’s the core team’s job). Some have expressed concern that the name “Security Working Group” might lead people to believe that we’re in charge of all security for the Rust project. As such, we’re going to try coming up with a different name, but we need suggestions! The name should be short and pithy, and should be consistent with our mission to make writing secure code easy. Some alternatives that have been proposed:

- Secure Code WG
- Ecosystem Security WG

If you have ideas, join the discussion [on Twitter](https://twitter.com/rustlang/status/1050663644009181186).

---

<div class="post-metadata">

**Author:** ![Shnatsel](https://sea2.discourse-cdn.com/flex002/user_avatar/internals.rust-lang.org/shnatsel/32/4613_2.png) [@Shnatsel](https://internals.rust-lang.org/u/Shnatsel)\
**Post date:** [October 14, 2018, 2:35pm UTC](https://internals.rust-lang.org/t/proposal-security-working-group/8282/135 "2018-10-14T14:35:44Z")

</div>

Nice!

Is anything decided on the communication channels? Basically, now that it’s a thing, how do I participate?

---

<div class="post-metadata">

**Author:** ![joshlf](https://sea2.discourse-cdn.com/flex002/user_avatar/internals.rust-lang.org/joshlf/32/3815_2.png) [@joshlf](https://internals.rust-lang.org/u/joshlf)\
**Post date:** [October 14, 2018, 5:38pm UTC](https://internals.rust-lang.org/t/proposal-security-working-group/8282/136 "2018-10-14T17:38:26Z")

</div>

> [@Shnatsel](#):
>
> Is anything decided on the communication channels? Basically, now that it’s a thing, how do I participate?

We're still working on that. We've got a [GitHub org](https://github.com/rust-secure-code) set up, but we're working on communication besides that. Our [administrative repo](https://github.com/rust-secure-code/wg) will have details once we've gotten the other stuff set up.

---

<div class="post-metadata">

**Author:** ![DrizztVD](https://sea2.discourse-cdn.com/flex002/user_avatar/internals.rust-lang.org/drizztvd/32/4521_2.png) [@DrizztVD](https://internals.rust-lang.org/u/DrizztVD)\
**Post date:** [October 14, 2018, 7:30pm UTC](https://internals.rust-lang.org/t/proposal-security-working-group/8282/137 "2018-10-14T19:30:08Z")

</div>

Sounds like a bootstrapping problem. How about if contributors want to help set things up?

---

<div class="post-metadata">

**Author:** ![joshlf](https://sea2.discourse-cdn.com/flex002/user_avatar/internals.rust-lang.org/joshlf/32/3815_2.png) [@joshlf](https://internals.rust-lang.org/u/joshlf)\
**Post date:** [October 14, 2018, 8:11pm UTC](https://internals.rust-lang.org/t/proposal-security-working-group/8282/138 "2018-10-14T20:11:48Z")

</div>

> [@DrizztVD](#):
>
> Sounds like a bootstrapping problem. How about if contributors want to help set things up?

It's getting a bit hard to coordinate with all of the cooks in the kitchen at this point, but I appreciate the offer! That said, we're looking to [design a logo](https://github.com/rust-secure-code/wg/issues/1) if that's the sort of thing you're into!

---

<div class="post-metadata">

**Author:** ![DrizztVD](https://sea2.discourse-cdn.com/flex002/user_avatar/internals.rust-lang.org/drizztvd/32/4521_2.png) [@DrizztVD](https://internals.rust-lang.org/u/DrizztVD)\
**Post date:** [October 14, 2018, 8:29pm UTC](https://internals.rust-lang.org/t/proposal-security-working-group/8282/139 "2018-10-14T20:29:00Z")

</div>

Sure, no problem, it’s called bootstrapping for a reason - pulling yourself up by your own bootstraps. The visibility of the process from my viewpoint is almost zero, though.

If you need the help, throw more tasks on this thread.

---

<div class="post-metadata">

**Author:** ![bascule](https://sea2.discourse-cdn.com/flex002/user_avatar/internals.rust-lang.org/bascule/32/3057_2.png) [@bascule](https://internals.rust-lang.org/u/bascule)\
**Post date:** [October 14, 2018, 9:30pm UTC](https://internals.rust-lang.org/t/proposal-security-working-group/8282/140 "2018-10-14T21:30:30Z")

</div>

> [@DrizztVD](#):
>
> If you need the help, throw more tasks on this thread.

Now that we have a GitHub repo, I'd suggest opening issues there rather than putting them here:

> **[Issues · rust-secure-code/wg](https://github.com/rust-secure-code/wg/issues)**
>
> Coordination repository for the Secure Code Working Group - Issues · rust-secure-code/wg

Things are easily lost in the shuffle here, and are easier to track and link to on GitHub. I'll open another to get things rolling... where to chat!

> <https://github.com/rust-secure-code/wg/issues/2>
>
> Zulip. IRC. Discord. Slack. Gitter. etc. There are lots of options. Where do we …want to chat?

[Previous page](https://internals.rust-lang.org/t/proposal-security-working-group/8282.md?page=6)

[Next page](https://internals.rust-lang.org/t/proposal-security-working-group/8282.md?page=8)
