Update security details in SECURITY.md

Clarified access and security details for the Hub, including SSH Remote Access and support access.
This commit is contained in:
Sovran Systems
2026-10-02 11:56:14 -05:00
committed by GitHub
parent c20a47bab7
commit 2867954808
+22 -16
View File
@@ -31,13 +31,11 @@ The Hub and core data run on operator-owned hardware. The Hub is for a trusted
local network and must not be port-forwarded to the internet. It uses HTTP, so local network and must not be port-forwarded to the internet. It uses HTTP, so
authentication does not encrypt local network traffic. authentication does not encrypt local network traffic.
The Hub is served on port 8937 and is not fronted by Caddy. The Hub is served on port 8937 and is not fronted by Caddy. Server + Desktop and
Bitcoin Node Only open that port in the firewall, so local devices reach the Hub
Server + Desktop and Bitcoin Node Only open that port in the firewall, so local devices reach the Hubat `http://sovransystemsos.local:8937`. at `http://sovransystemsos.local:8937`. On Desktop Only the Hub is not published
at all: reachable only from the machine itself, on localhost, with no TCP port
On Desktop Only the Hub is not published at all: reachable only from the machine itself, on localhost, with no TCP port
open in the firewall (UDP 5353 for mDNS only). open in the firewall (UDP 5353 for mDNS only).
`sovran_systemsOS.hub.directPort = true` in `custom.nix` opens port 8937 if you `sovran_systemsOS.hub.directPort = true` in `custom.nix` opens port 8937 if you
want to reach a Desktop Only Hub from another device. want to reach a Desktop Only Hub from another device.
@@ -60,17 +58,16 @@ for what this means and the alternatives.
### Bitcoin stack ### Bitcoin stack
Bitcoin and Lightning modules are maintained in the standalone Bitcoin and Lightning modules live in the standalone
[Sovran_Bitcoin](https://github.com/naturallaw777/Sovran_Bitcoin) repository [Sovran_Bitcoin](https://github.com/naturallaw777/Sovran_Bitcoin) repository,
and consumed as a flake input. OS-specific customizations (Second_Drive paths, consumed as a flake input and bridged by
operator user, Hub integration) are bridged by `modules/sovran-bitcoin-integration.nix`. The `nix-bitcoin.*` namespace and
`modules/sovran-bitcoin-integration.nix`. The `nix-bitcoin.*` option namespace `/etc/nix-bitcoin-secrets` path remain only for upgrade compatibility.
and `/etc/nix-bitcoin-secrets` path remain only for upgrade compatibility.
### Supply chain and integrity ### Supply chain and integrity
`flake.lock` pins flake inputs, and fetched source archives use fixed hashes. `flake.lock` pins flake inputs, and fetched source archives use fixed hashes.
Builds still depend on pinned Nixpkgs, NixVim, btc-clients-nix, upstream source Builds still depend on pinned Nixpkgs and other inputs, upstream source
archives, and any configured binary cache. archives, and any configured binary cache.
The Hub integrity check verifies Nix store contents against a build from local The Hub integrity check verifies Nix store contents against a build from local
@@ -80,22 +77,31 @@ an attacker who already controls root.
### Access and service isolation ### Access and service isolation
- Firewall enabled by default - Firewall enabled by default
- Public SSH and remote desktop disabled by default - SSH Remote Access and remote desktop disabled by default
- Separate service users and systemd sandboxing where supported - Separate service users and systemd sandboxing where supported
- Administrative service ports bound to loopback where practical - Administrative service ports bound to loopback where practical
- Tor enforced for supported Bitcoin traffic and onion services - Tor enforced for supported Bitcoin traffic and onion services
- Public web services exposed only when enabled by the operator (this makes - Public web services exposed only when enabled by the operator (this makes
your home IP address public) your home IP address public)
SSH Remote Access is the only supported administrative port that faces the
network, and it is off by default. Enabling it listens on all interfaces and
opens TCP port 22; the Hub then asks you to forward port 22, which puts SSH on
the public internet. Key authentication only. Turn it off when you are done.
Tor reduces network exposure for configured Bitcoin services. It is not a Tor reduces network exposure for configured Bitcoin services. It is not a
guarantee against every IP leak, application bug, or traffic-analysis attack. guarantee against every IP leak, application bug, or traffic-analysis attack.
### Restricted support access ### Restricted support access
Support uses a per-session SSH key on the non-root `sovran-support` account. Tech Support runs over SSH, and the Hub refuses to start a session until SSH
Remote Access is enabled (see above). Support uses a per-session SSH key on the
non-root `sovran-support` account.
Sessions expire after 24 hours and have a small allowlist of `sudo` commands. Sessions expire after 24 hours and have a small allowlist of `sudo` commands.
Wallet paths receive deny ACLs unless the operator explicitly removes them. Wallet paths receive deny ACLs unless the operator explicitly removes them.
Disabling support removes the key and reapplies the ACLs. Disabling support removes the key and reapplies the ACLs but leaves SSH
enabled.
Support events are written to `/var/log/sovran-support-audit.log`. This is a Support events are written to `/var/log/sovran-support-audit.log`. This is a
local audit log, not a cryptographically tamper-evident record. local audit log, not a cryptographically tamper-evident record.