Skip to main content

Remediation

Research, not an audit
These pages are research and development and may not match the live app. Do not treat this as an audit. Shared for testing and demo only. Please use responsibly.

Recommendations for findings that remain Confirmed or Accepted in this draft. Mitigated Medium work from the prior pass (CSP, host allowlist, fail-closed cascade, sealed tokens, hello→active, vendored git, peer ciphertext redact) is not repeated here.

Medium​

IDRecommendation
GLITR-2026-001Keep the concurrent-init product rule documented next to maybe_yield_initiator. Do not claim Signal-spec session setup under glare. Cross-library tests already cover winner follow-up.
GLITR-2026-002Prefer N-party GroupSession for group chat payloads; keep pairwise cascade as the delivery envelope only. Do not claim PCS on membership change unless add/remove commits were processed.
GLITR-2026-003ICE/media over Tor remains out of reach without custom ICE/TURN-over-onion. Keep contact-details copy that signaling prefers onion when tor+webrtc are on, and that STUN/direct paths may still apply.

Low​

IDRecommendation
GLITR-2026-004Prompt for camera/mic on Linux desktop instead of auto-allow when the WebKit API allows it.
GLITR-2026-005Replace mobile Arti dangerously_trust_everyone with a reviewed trust policy when Tor on mobile is product-ready.
GLITR-2026-006Narrow document::eval bridges; if CSP can drop unsafe-eval after Dioxus changes, do so.
GLITR-2026-007Prefer a stable local committer identity derived from profile without leaking PII.

Accepted (no code change required)​

IDNote
GLITR-2026-008–010Threat-model leftovers.
GLITR-2026-011Intentional: peers retrieve ciphertext envelopes they can decrypt; plaintext body is redacted on Peer RPC.

Catalog: Findings.