1 |
On Sun, 2018-08-19 at 14:42 -0400, Aaron Bauman wrote: |
2 |
> Gentoo-bug: https://bugs.gentoo.org/659620 |
3 |
> |
4 |
> All, this email will serve as a comparison between the two vendors which |
5 |
> have provided quotes to the Foundation. This does not include Alice's |
6 |
> proposal as U2FZero is currently out of stock in the United States and |
7 |
> does not seem to offer any availability in Asia. Alice did suggest that |
8 |
> we split vendors across geographical markets, but I find this will make |
9 |
> the situation become very difficult to handle. It would also put the |
10 |
> burden on individuals to receive and disperse the tokens and increase |
11 |
> shipping costs, burden the treasurer for reimbursements to be processed, |
12 |
> and possibly cause delays. |
13 |
> |
14 |
> Yubikey: |
15 |
> |
16 |
> Quote received for (150) Yubikey FIPS tokens. |
17 |
> |
18 |
> Unit Price: $44.16 USD |
19 |
> Total: $6,624 USD |
20 |
> Discount: 4% (already available to anyone ordering in bulk) |
21 |
> |
22 |
> Shipping costs can be found at [1] and the lowest cost projections |
23 |
> given. They do not offer any standard costs for shipping and cannot |
24 |
> discount it. |
25 |
> |
26 |
> Open source: Several products are no longer open sourced and tracking |
27 |
> which is/is not can be difficult [4]. |
28 |
> |
29 |
> Nitrokey: |
30 |
> |
31 |
> Quote received based on (150) Nitrokey Pro tokens. |
32 |
> |
33 |
> Unit Price: 27,59 € ($31.58 USD at the time of this email) |
34 |
> Total: 4,138.50 € ($4737.06 USD at the time of this email) |
35 |
> Discount: 33% (With sponsorship agreement on gentoo.org) |
36 |
> |
37 |
> All prices are already inclusive of VAT. |
38 |
> |
39 |
> Shipping times can be found here [2]. Shipping costs can be found here |
40 |
> [3]. The most expensive shipping is worldwide starting at 7,40 € |
41 |
> ($8.47 USD at the the time of this email). |
42 |
> |
43 |
> Nitrokey has also offered several unique options for Gentoo. They will |
44 |
> provide a custom portal which allows each developer to request their |
45 |
> security token. This is done via a Foundation (infra really) provided |
46 |
> list of valid gentoo.org email addresses. Additionally, they will |
47 |
> provide monthly billing of all purchased devices and the Foundation is |
48 |
> not obligated to purchase all (150) tokens. This can be a standing |
49 |
> agreement until the Foundation decides to remove financial support. |
50 |
> |
51 |
> Considering both vendors, we can estimate shipping at the highest cost |
52 |
> in order to best prepare for potential expenses. |
53 |
> |
54 |
> Open source: All products are considered open [4]. |
55 |
> |
56 |
> ----- |
57 |
> |
58 |
> Motion: I move that the board vote to accept the offer from Yubico or |
59 |
> Nitrokey and begin our agreement with the accepted vendor beginning 1 |
60 |
> September 2018. This motion will provide security tokens to all current |
61 |
> developers listed in Gentoo's LDAP infrastructure as of 31 August 2018. |
62 |
> |
63 |
> Motion: I move that the board vote to maintain the aforementioned |
64 |
> agreement in order to support future Gentoo developers with security |
65 |
> tokens. This motion includes the right to terminate future purchases |
66 |
> based on the Foundation's financials. |
67 |
> |
68 |
> [1]: https://www.yubico.com/support/shipping-and-buying-information/ |
69 |
> [2]: https://www.nitrokey.com/documentation/frequently-asked-questions#how-long-does-the-shipping-take |
70 |
> [3]: https://shop.nitrokey.com/shop/product/nitrokey-pro-2-3 |
71 |
> [4]: https://old.lwn.net/Articles/736231/ |
72 |
|
73 |
1. Should we include all developers or only developers with gentoo.git |
74 |
commit access? |
75 |
|
76 |
2. Shouldn't we set some minimal time-as-a-dev for this? |
77 |
|
78 |
What I'm concerned about are people joining Gentoo only to get the free |
79 |
token and then stopping to contribute. We historically had both cases |
80 |
of people joining and then disappearing shortly afterwards, and people |
81 |
trying to join just to gain the developer status and not to contribute. |
82 |
|
83 |
Alternatively, require developers to return the token upon termination |
84 |
of developer status, with allowance that after X years as a dev |
85 |
the token is considered scrapped and does not need to be returned. |
86 |
|
87 |
-- |
88 |
Best regards, |
89 |
Michał Górny |