Skip to main content

Methodology

Research, not an audit
These pages are research and development and may not match the live app. Do not treat this as an audit. Shared for testing and demo only. Please use responsibly.

This page says how the draft in-house review was done. It is not a rules-of-engagement letter from a firm, and it is not a claim that every path was executed at runtime. The catalog describes the current app; it is not a changelog of prior drafts.

FieldValue
Date4 October 2026
SubjectAssembled client starting at whatsup (current tree)
MethodStatic review of workspace source, schemas, and tests
Not doneIndependent firm, live pentest, side-channel lab, hosted-header inspection

What was reviewed​

The review started at /whatsup and followed Cargo.toml path dependencies and ApiHandle::dispatch routes. Sibling crates were read only as far as the shell uses them.

Review unitPrimary evidence
IdentityPOST /profile/setup, POST /peer/hello, safety_number, Pair now / onion adopt
Recipient cascadeapi-core cascade_msg, crypto-cascade product / wire (product path; not mls-layer)
Password at restdb-core encryption, SavedConnect, TUI merge_mailbox
Git deliverymessages_send / messages_poll, PeerReader, git-web.js
Live data channelwhatsup live.rs, webrtc-peer.js, webrtc-core chat / RPC
Device pairdevice_pair.rs, GET /devices/snapshot, merge apply
Tortor-core session, glitr-client tor_native / proxy
Web / PWAsw.js, register-sw.js, sessionStorage bridge, CSP meta injected by build-pwa.sh (unsafe-eval for Dioxus), vendored isomorphic-git
Local vs Peer authzrequire_local, RequestSource::Peer, generated /resources/*

Threat-model pages were treated as the intent catalog. This folder records whether the current code matches that intent, and where it adds a finding the leftover list already named.

What was not done​

ActivityWhy it is absent
Independent third-party auditNot commissioned. This folder does not stand in for one.
Dynamic penetration test of a hosted mailboxNo engagement against a live git host, CORS proxy, or STUN operator
Side-channel / constant-time labRelies on dalek, libcrux, and aes-gcm; no project-wide policy
Hosted Content-Security-Policy header inspectionMeta CSP is injected at PWA build time; deploy hosts may still add headers
Binary / WASM reproducible-build checkNot claimed on the roadmap
Fuzzing the assembled messengerLibrary fuzz targets exist; they are not a product program
Review of gallery-only ICE / TURN presetsMarked Out of scope unless whatsup ships them

A green CI job on a handshake library is not a review of send, poll, or merge. The verification report already draws that line.

How findings were written​

Each finding has an ID (GLITR-2026-NNN), a severity, a status, a one-line impact, and a surface page. Evidence is a path and a function. Recommended fixes live on Remediation.

Severity is impact on a shipped path, not a CVSS calculator:

SeverityUsed when
CriticalLong-term keys or the mailbox password are shared, reused, or written where a same-origin script or a completed pair can take them
HighA third party on a default path sees credentials or can weaken a handshake layer
MediumA control is missing, platform-specific, or easy to bypass without immediately handing over long-term keys
LowHygiene, platform spike, or a correlatable artifact
InfoPositive control, or an explicit non-finding

Confirmed means the code was read in this workspace on the report date. This draft describes the current app only — fixed issues are omitted from the catalog rather than kept as history. Mitigated is reserved if a Confirmed row is later fixed while the section remains an open draft. If a pass weakens a claim, drop or downgrade the row.

Honesty rule​

You may cite this folder as a draft in-house implementation review. You may not cite it as an independent audit, a pentest report, or a reason to put sensitive details in the demo.

How this method and the Glitr bar sit next to OWASP ASVS/MASVS, NIST SSDF, and named protocol specs: Standards comparison.

Start of this folder: Security audit. Dated view: Report.