I was surprised to see this published. From the earlier discussion on
the Commons Security list
(https://lists.apache.org/thread/dw992t9771drg3gjfqo2zvxkr8vpqxvg) my
understanding (which I also stated in that thread) was that the model
proposed there was longer-term intended to grow into a holistic
public-facing threat/security model, but that for the foreseeable
future it was only meant to inform the internal LLM audits, not
something we'd publicly commit to.

I think this model is too ambitious. For the internal LLM audit that
is no problem: worst-case it'd find some things that we'd end up
fixing as hardening instead of as vulnerabilities. For posting
publicly I think it is a problem: it means we're making a public
commitment to promises that I'm not sure we're ready to commit to.

For example, the model claims:

===
for Compress, Configuration, Text, and FileUpload, passing any data to
them in their default configuration will not:

    cause excessive CPU consumption,
    cause excessive memory allocation,
===

Do we really have consensus that this is something we want to commit
to? TBH I don't think we have the bandwidth to make good on that
promise, and I don't think it's necessary.


Kind regards,

Arnout

On Tue, Sep 22, 2026 at 9:09 PM Gary D. Gregory <[email protected]> wrote:
>
> Fixed typo in the subject.
>
> Gary
>
> On 2026/09/22 17:47:18 Gary Gregory wrote:
> > Hi All,
> >
> > Thank you to Piotr for helping get our threat model off the ground.
> >
> > Please review for content and typos, if you feel so inclined:
> >
> > - https://commons.apache.org/threat-model-short-0.1.0.html
> > - https://commons.apache.org/threat-model-0.1.0.html
> >
> > Both are linked from https://commons.apache.org/security.html
> >
> > TY,
> > Gary
> >
> > ---------------------------------------------------------------------
> > To unsubscribe, e-mail: [email protected]
> > For additional commands, e-mail: [email protected]
> >
> >
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: [email protected]
> For additional commands, e-mail: [email protected]
>


-- 
Arnout Engelen
ASF Security Response
Apache Pekko PMC member, ASF Member
NixOS Committer
Independent Open Source consultant

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to