Skip to main content

Live and WebRTC

Research, not an audit
These pages are research and development and may not match the live app. Do not treat this as an audit. Shared for testing and demo only. Please use responsibly.

Online path: SDP + ICE, then a DTLS data channel, then application frames. Product page: Live links. Shell: whatsup live.rs, assets/webrtc-peer.js.

There is no Glitr signaling server. Git-brokered offer/answer rows are cascaded to the contact. When a contact has tor and webrtc enabled and a peer onion is known, auto git-signaling offers are skipped so onion can carry live setup faster. Pair-now invites remain OOB.

GLITR-2026-003 — ICE/media may still be direct​

Medium · Confirmed

Per-contact STUN dropdown and force-STUN (host-candidate filter) are on contact details. Default STUN remains Google’s public server when unset. Onion-preferred signaling does not put ICE/media on Tor. Without TURN, force-STUN cannot force a true relay path.

Residual. Documented on the contact-details prefs copy. Anonymity for live media is a non-goal.

GLITR-2026-011 — peer RPC ciphertext​

Accepted

RequestSource::Peer may list non-@encrypted outbound / profile-public / receipts. Peer list/get redacts plaintext body on outbound rows. Peers retrieve ciphertext they can decrypt for themselves — intentional mailbox semantics on the live link.

GLITR-2026-004 — Linux WebKit permissions​

Low · Confirmed

whatsup linux_webrtc.rs auto-allows camera / mic / device-info requests.

Out of scope

Gallery OpenRelay TURN is not the Glitr / whatsup default ICE set.

GLITR-2026-018 — per-contact transport prefs​

Info

Contact fields gitEnabled / torEnabled / webrtcEnabled (default on), stunUrl, forceStun. UI on contact details. allow_git_url uses parsed host equality (not prefix match).

Tor split residual: GLITR-2026-003 (same ICE residual).

Fixes: Remediation. Catalog: Findings.