Skip to content
Snippets Groups Projects
unified-data-policy.md 1.68 KiB
Newer Older
Recolic K's avatar
Recolic K committed
# Unified data policy

## Replication policies

- Level 4: at least 4 copies, in 3 location, 2 countries, 2 continents. 

- Level 3: at least 3 copies, in 2 location, 2 countries. 

- Level 2: at least 2 copies. 

- Level 1: at least 1 copies. 

## Confidential Policies

> `sensitive` means I don't want to leak it, `important` means I don't want to lost it. 

Recolic's avatar
Recolic committed
- type I2: non-sensitive important data, such as environent setup script, software installation packs, saved movies.
Recolic K's avatar
Recolic K committed

Recolic's avatar
Recolic committed
- type I: public personal data, or non-important public data.
Recolic K's avatar
Recolic K committed

Recolic's avatar
Recolic committed
- type C2: sensitive important personal data, such as photos, game save, server data.
Recolic K's avatar
Recolic K committed

Recolic's avatar
Recolic committed
- type C: sensitive non-important personal data, such as system logs, chat logs, screenshots, web history, development environment.
Recolic K's avatar
Recolic K committed

Recolic's avatar
Recolic committed
- type M: secret keys/seeds/passwords, banking account/card information.
Recolic K's avatar
Recolic K committed

- type MX: GPG masterkey itself. 

- [TODO]X

Recolic's avatar
Recolic committed
> **super key doesn't not apply any data policy, only allowed to store in-brain.** 
Recolic K's avatar
Recolic K committed

|Type|Encryption|Ownership|Replication|Current\_Solution|
|---|---|---|---|---|
Recolic's avatar
Recolic committed
|MX|Always, by cold key and super key|1P|Level 4|nfs/backup/MX|
Recolic's avatar
Recolic committed
|M|Always, by GPG master key or super key|1P|Level 4|nfs/backup/C2_M|
|C2|Only on untrusted device|1P / 3P|Level 3|nfs/backup/C2_M, RecoDrive|
|C|Device-level encryption|1P / 3P|Level 1|any encrypted devices|
Recolic's avatar
Recolic committed
|I2|Optional|1P / 3P|Level 2|nfs/backup/I2, RecoGit, RecoDrive|
Recolic's avatar
Recolic committed
|I|Optional|1P / 3P|Level 1|any devices|
Recolic K's avatar
Recolic K committed

|Properties|Important|Non-Important|
|---|---|---|
Recolic's avatar
Recolic committed
|Sensitive|MX,M,C2|C|
|Non-sensitive|I2|I|
Recolic K's avatar
Recolic K committed

Recolic's avatar
.  
Recolic committed
![](./.res/reco-file-types.png)
Recolic's avatar
.  
Recolic committed

All device storing / processing unencrypted sensitive data, must either using Fully-Open-Source-Software, or be disconnected from Internet and destroyed afterward.