Skip to main content

Cryptography

Research, not an audit
These pages are research and development and may not match the live app. Do not treat this as an audit. Shared for testing and demo only. Please use responsibly.

Recipient messages use cascade v3 only: AES → MLS → Signal → PQXDH, then RSA hybrid → ML-KEM. Handshakes (including MLS welcome) ride inside the outer wrap.

Password sealing of @encrypted mailbox types is a different job (Argon2id → AES-GCM).

Pairwise vs group MLS. The inner mls layer is a 2-party MLS group per contact (defense-in-depth). Glitr group threads use a separate sealed GroupProtocolSession (GroupSession) so the chat plaintext is one N-party MLS application ciphertext. Group-MLS envelopes are delivered with an outer-only RSA+ML-KEM seal (seal_outer_for_peer) so the recipient’s published MLS key package is not also consumed by a pairwise MLS welcome on the same send. Details: MLS pairwise review.

GLITR-2026-001 — concurrent-init tie-break​

Medium · Confirmed

maybe_yield_initiator documents a product rule: on dual first-message glare, the lexicographically larger Signal identity drops its initiator session and becomes responder. This is not a Signal-spec procedure. In-crate tests cover winner follow-up after glare. Signal, PQXDH, and pairwise MLS clear together.

Residual. Do not claim spec-faithful session setup under concurrent init. There is no ProVerif messenger model for this rule.

GLITR-2026-002 — groups and N-party MLS​

Medium · Mitigated

Historically messages_send fan-out encrypted the chat plaintext once per member with independent pairwise cascades. The product path now encrypts group chat payloads with shared N-party MLS (GroupSession), then delivers the group-MLS envelope with per-member outer RSA+ML-KEM seals. Membership add/remove advances the MLS epoch (welcome + commits). Residual: BasicCredential only; no external join; unaudited mls-rs façade.

GLITR-2026-014 — cascade v3 fail-closed​

Info

  • Encrypt refuses missing local secrets or peer protocolBundles (no v1 RSA hybrid fallback).
  • Decrypt rejects non-cascade and legacy v2 envelopes.
  • recipientPublicKey overrides on send/signaling are rejected.
  • Signed Signal SPKs, OTPK pool, and rotate-prekeys remain in place.
  • Pairwise MLS welcome is mandatory on first message; session establishment requires mls_group_state.

Fixes: Remediation. Catalog: Findings.