Cryptography
Recipient messages use cascade v3 only: AES → MLS → Signal → PQXDH, then RSA hybrid → ML-KEM. Handshakes (including MLS welcome) ride inside the outer wrap.
Password sealing of @encrypted mailbox types is a different job (Argon2id → AES-GCM).
Pairwise vs group MLS. The inner mls layer is a 2-party MLS group per contact (defense-in-depth). Glitr group threads use a separate sealed GroupProtocolSession (GroupSession) so the chat plaintext is one N-party MLS application ciphertext. Group-MLS envelopes are delivered with an outer-only RSA+ML-KEM seal (seal_outer_for_peer) so the recipient’s published MLS key package is not also consumed by a pairwise MLS welcome on the same send. Details: MLS pairwise review.
GLITR-2026-001 — concurrent-init tie-break
Medium · Confirmed
maybe_yield_initiator documents a product rule: on dual first-message glare, the lexicographically larger Signal identity drops its initiator session and becomes responder. This is not a Signal-spec procedure. In-crate tests cover winner follow-up after glare. Signal, PQXDH, and pairwise MLS clear together.
Residual. Do not claim spec-faithful session setup under concurrent init. There is no ProVerif messenger model for this rule.
GLITR-2026-002 — groups and N-party MLS
Medium · Mitigated
Historically messages_send fan-out encrypted the chat plaintext once per member with independent pairwise cascades. The product path now encrypts group chat payloads with shared N-party MLS (GroupSession), then delivers the group-MLS envelope with per-member outer RSA+ML-KEM seals. Membership add/remove advances the MLS epoch (welcome + commits). Residual: BasicCredential only; no external join; unaudited mls-rs façade.
GLITR-2026-014 — cascade v3 fail-closed
Info
- Encrypt refuses missing local secrets or peer
protocolBundles(no v1 RSA hybrid fallback). - Decrypt rejects non-cascade and legacy v2 envelopes.
recipientPublicKeyoverrides on send/signaling are rejected.- Signed Signal SPKs, OTPK pool, and rotate-prekeys remain in place.
- Pairwise MLS welcome is mandatory on first message; session establishment requires
mls_group_state.
Fixes: Remediation. Catalog: Findings.
