Security-audit report
This report is for product readers, then developers and security reviewers. It summarizes a draft in-house implementation review of the assembled client as it stands. It is not an independent audit, not a theorem, not a score against another app, and not locked to a release tag.
| Field | Value |
|---|---|
| Date | 4 October 2026 |
| Subject | Glitr product (whatsup + in-process stack) |
| Audience | Product / exec readers, then developers and security reviewers |
| Status | Draft in-house review — not an independent audit |
| Not claimed | Formal verification of the messenger; anonymity; nation-state safety |
Jump to: Executive summary · Counts · Glitr bar · You may say / may not
Catalog: Findings. Method: Methodology. Standards map: Standards comparison. Product leftover: Residual risk. Library models: Verification report.
How to read the words
| Word | Meaning |
|---|---|
| Critical / High / Medium / Low / Info | Impact if the finding is real on a shipped path |
| Confirmed | Observed in current code |
| Mitigated | Reserved: a Confirmed claim that later stops holding on the shipped path (unused in this draft) |
| Accepted | Known residual already on the threat-model leftover list |
| Out of scope | Not used by whatsup |
These words are not proofs. They are not the formal-verification words (Tested / Modeled / Type-checked). They do not upgrade a threat-model Open row into “audited.”
The roadmap row Regular security audits stays planned. Independent audit of the messenger stays Open.
Executive summary
On the Glitr bar today. api-core is in process. There is no Glitr account server. Web first-run generates a real RSA-4096 identity (WebCrypto on wasm). Recipient bodies use cascade v3 only and fail closed without peer protocolBundles. Signal signed prekeys are verified; OTPK pools and rotate-prekeys exist. Device-pair data-channel snapshots are public mailbox rows only. GUI and TUI do not persist the unlock password or git tokens in glitr:connect. Production PWA injects a CSP and vendors isomorphic-git same-origin. Hello Match/Store promotes contacts to active. Peer RPC redacts outbound plaintext body. The web git path has no default third-party CORS proxy. Chat text is an escaped text node. There is no Web Push surface.
Outstanding on the Glitr bar. A user-supplied CORS proxy still sees git HTTP. Git still cannot burn one-time prekeys for every fetcher. Public STUN / ICE and plaintext wu1: / on1: invites leak introduction metadata. Onion-preferred WebRTC signaling does not put ICE/media on Tor. Open Medium rows are concurrent-init honesty and the ICE residual; group MLS is Mitigated via GroupSession.
Independent audit. Not done. This report does not change that sentence.
The app is shared for testing and demo. Do not put sensitive details in it.
Counts
| Severity | Confirmed | Mitigated | Accepted | Out of scope | Info |
|---|---|---|---|---|---|
| Critical | 0 | 0 | 0 | 0 | 0 |
| High | 0 | 0 | 0 | 0 | 0 |
| Medium | 2 | 0 | 1 | 0 | 0 |
| Low | 4 | 0 | 0 | 0 | 0 |
| Residual / other | 0 | 0 | 4 | 1 | 9 |
| Total IDs | 6 | 0 | 5 | 1 | 9 |
The full table is on Findings.
Glitr bar
Protect message content from the host. Do not expect the host to be unaware that you chat. Status words here are the threat-model words. The Finding column cites this draft only when a catalog row applies.
Transport
| Property | Status | Finding |
|---|---|---|
| No Glitr chat or account server | Mitigated | In-process api-core. |
| Git mailbox you own | Documented | GLITR-2026-008 host metadata remains Accepted. |
| Live WebRTC is peer-to-peer | Documented | GLITR-2026-003 ICE/STUN residual. |
| Native onion live path | Partial | Onion-preferred signaling when tor+webrtc; ICE/media may still be direct (GLITR-2026-003). Browser does not run Arti. |
| Web git path | Partial | No default public proxy. A user-supplied proxy is still a credential intermediary. |
Encryption
| Property | Status | Finding |
|---|---|---|
| Recipient cascade on bodies and files | Mitigated | Cascade v3 fail-closed without protocolBundles (GLITR-2026-014). |
| Pair now / onion invite confidentiality | Partial | GLITR-2026-009 Accepted. |
| Forward secrecy as a product claim | Partial | Library Double Ratchet + signed SPKs / OTPK pool. Git still cannot burn OTPKs. Concurrent-init is a custom rule (GLITR-2026-001). |
| Groups | Partial | GLITR-2026-002 N-party GroupSession Mitigated; delivery remains per-member seals. |
Identity and devices
| Property | Status | Finding |
|---|---|---|
| TOFU + safety number | Partial | GLITR-2026-015. Hello Match/Store promotes active (GLITR-2026-019). |
| Web first-run identity | Mitigated | WebCrypto RSA-4096. |
| GUI unlock-password / token persist | Mitigated | GLITR-2026-013. |
| Multi-device pair snapshot | Mitigated | DC uses public pair_snapshot only. |
Trust documentation
| Property | Status | Finding |
|---|---|---|
| Product threat-model draft | Documented | Unchanged. |
| Library formal verification | Documented | Unchanged. Messenger not claimed. |
| In-house implementation review | Documented | This folder (draft). |
| Independent audit of the messenger | Open | GLITR-2026-010. |
You may say / you may not
What you can say in a review without treating this page as an independent audit.
You may say
- A draft in-house implementation review of the assembled client exists, dated 4 October 2026.
- This draft has no Critical or High findings. Medium and Low rows are in the catalog.
- Web first-run uses real RSA. Device-pair DC snapshots omit long-term secrets. Unlock password and git tokens are not persisted in
glitr:connect. Signal SPKs are signed and verified. - A user-supplied CORS proxy still sees git HTTP. ICE/STUN may still reveal addresses even when Tor is on for signaling.
- Message bodies require protocol bundles (cascade v3). Groups use N-party MLS with per-member delivery seals.
- Four libraries have models. The messenger does not claim formal verification.
- Independent audit of the messenger is still not done.
You may not say
- Glitr has been independently audited, or this folder counts as that audit.
- The messenger is formally verified, anonymous, or production-ready.
- An empty Critical/High section means there are no open Critical/High rows; Medium residuals remain.
- DTLS is enough for chat bodies or files.
- Pair now or onion QR invites are confidential.
- ProVerif covers the git host, a CORS proxy, or a stolen device.
- A self-authored or AI-authored review replaces a third-party audit.
- Rust, a cascade stack, or library proofs make a stolen unlocked session safe.
FAQ sentence: Glitr aims to keep message content from the host. It does not hide that you chat. This report is a draft in-house review. The app is a demo. Do not put sensitive details in it.
Start of this folder: Security audit. Catalog: Findings. Leftover: Residual risk.
