Proposal: Security Working Group

Yep. Those Web for Pentester exercises makes one think a bunch of kindergarten kids built the Web 1.0 (that would be a joke if it wasn’t so true btw). Although, hindsight vision is perfect, and China wasn’t spying on everyone back then (yep, only the NSA was).

What would be a complete joke, however, is if Web 3.0 did not manage to correct those mistakes. So, there is the opportunity to do plenty of good here. It would be necessary to talk about how exactly to promote the security of existing crates while not blocking emerging crates. Rust crates should also be smaller and application-specific (based on what I think the community prefers) while not too small so that when the maintainers immigrate to Mars the crate can live on.

Thus, it can be seen that a Security WG would be a superset of a Crates WG, and ultimately they may need to be granted benevolent dictatorship status over certain aspects of crates.io, or otherwise, how are they going to lovingly force Rustacean minions into secure coding practices?

Hence, we can see that Rust Security WG could (should) end up having the same impact as the Rust borrow-checker on newcomers. aka Rustacean-shrimp one week in: “My crate is at version 0.9.0 but it won’t let me publish version 1.0.0 of my crate!” 3 Months later after reading the Security Chapter in The Book and some Unsafe Guidelines: “Ooo, I see, it prevented me from pointing a loaded multi-barrel machine gun at my own foot and my friends’ heads”

1 Like