Skip to main content

Security-audit report

Research, not an audit
These pages are research and development and may not match the live app. Do not treat this as an audit. Shared for testing and demo only. Please use responsibly.

This report is for product readers, then developers and security reviewers. It summarizes a draft in-house implementation review of the assembled client as it stands. It is not an independent audit, not a theorem, not a score against another app, and not locked to a release tag.

FieldValue
Date4 October 2026
SubjectGlitr product (whatsup + in-process stack)
AudienceProduct / exec readers, then developers and security reviewers
StatusDraft in-house review — not an independent audit
Not claimedFormal verification of the messenger; anonymity; nation-state safety

Jump to: Executive summary · Counts · Glitr bar · You may say / may not

Catalog: Findings. Method: Methodology. Standards map: Standards comparison. Product leftover: Residual risk. Library models: Verification report.

How to read the words​

WordMeaning
Critical / High / Medium / Low / InfoImpact if the finding is real on a shipped path
ConfirmedObserved in current code
MitigatedReserved: a Confirmed claim that later stops holding on the shipped path (unused in this draft)
AcceptedKnown residual already on the threat-model leftover list
Out of scopeNot used by whatsup

These words are not proofs. They are not the formal-verification words (Tested / Modeled / Type-checked). They do not upgrade a threat-model Open row into “audited.”

The roadmap row Regular security audits stays planned. Independent audit of the messenger stays Open.

Executive summary​

On the Glitr bar today. api-core is in process. There is no Glitr account server. Web first-run generates a real RSA-4096 identity (WebCrypto on wasm). Recipient bodies use cascade v3 only and fail closed without peer protocolBundles. Signal signed prekeys are verified; OTPK pools and rotate-prekeys exist. Device-pair data-channel snapshots are public mailbox rows only. GUI and TUI do not persist the unlock password or git tokens in glitr:connect. Production PWA injects a CSP and vendors isomorphic-git same-origin. Hello Match/Store promotes contacts to active. Peer RPC redacts outbound plaintext body. The web git path has no default third-party CORS proxy. Chat text is an escaped text node. There is no Web Push surface.

Outstanding on the Glitr bar. A user-supplied CORS proxy still sees git HTTP. Git still cannot burn one-time prekeys for every fetcher. Public STUN / ICE and plaintext wu1: / on1: invites leak introduction metadata. Onion-preferred WebRTC signaling does not put ICE/media on Tor. Open Medium rows are concurrent-init honesty and the ICE residual; group MLS is Mitigated via GroupSession.

Independent audit. Not done. This report does not change that sentence.

The app is shared for testing and demo. Do not put sensitive details in it.

Counts​

SeverityConfirmedMitigatedAcceptedOut of scopeInfo
Critical00000
High00000
Medium20100
Low40000
Residual / other00419
Total IDs60519

The full table is on Findings.

Glitr bar​

Protect message content from the host. Do not expect the host to be unaware that you chat. Status words here are the threat-model words. The Finding column cites this draft only when a catalog row applies.

Transport​

PropertyStatusFinding
No Glitr chat or account serverMitigatedIn-process api-core.
Git mailbox you ownDocumentedGLITR-2026-008 host metadata remains Accepted.
Live WebRTC is peer-to-peerDocumentedGLITR-2026-003 ICE/STUN residual.
Native onion live pathPartialOnion-preferred signaling when tor+webrtc; ICE/media may still be direct (GLITR-2026-003). Browser does not run Arti.
Web git pathPartialNo default public proxy. A user-supplied proxy is still a credential intermediary.

Encryption​

PropertyStatusFinding
Recipient cascade on bodies and filesMitigatedCascade v3 fail-closed without protocolBundles (GLITR-2026-014).
Pair now / onion invite confidentialityPartialGLITR-2026-009 Accepted.
Forward secrecy as a product claimPartialLibrary Double Ratchet + signed SPKs / OTPK pool. Git still cannot burn OTPKs. Concurrent-init is a custom rule (GLITR-2026-001).
GroupsPartialGLITR-2026-002 N-party GroupSession Mitigated; delivery remains per-member seals.

Identity and devices​

PropertyStatusFinding
TOFU + safety numberPartialGLITR-2026-015. Hello Match/Store promotes active (GLITR-2026-019).
Web first-run identityMitigatedWebCrypto RSA-4096.
GUI unlock-password / token persistMitigatedGLITR-2026-013.
Multi-device pair snapshotMitigatedDC uses public pair_snapshot only.

Trust documentation​

PropertyStatusFinding
Product threat-model draftDocumentedUnchanged.
Library formal verificationDocumentedUnchanged. Messenger not claimed.
In-house implementation reviewDocumentedThis folder (draft).
Independent audit of the messengerOpenGLITR-2026-010.

You may say / you may not​

What you can say in a review without treating this page as an independent audit.

You may say​

  • A draft in-house implementation review of the assembled client exists, dated 4 October 2026.
  • This draft has no Critical or High findings. Medium and Low rows are in the catalog.
  • Web first-run uses real RSA. Device-pair DC snapshots omit long-term secrets. Unlock password and git tokens are not persisted in glitr:connect. Signal SPKs are signed and verified.
  • A user-supplied CORS proxy still sees git HTTP. ICE/STUN may still reveal addresses even when Tor is on for signaling.
  • Message bodies require protocol bundles (cascade v3). Groups use N-party MLS with per-member delivery seals.
  • Four libraries have models. The messenger does not claim formal verification.
  • Independent audit of the messenger is still not done.

You may not say​

  • Glitr has been independently audited, or this folder counts as that audit.
  • The messenger is formally verified, anonymous, or production-ready.
  • An empty Critical/High section means there are no open Critical/High rows; Medium residuals remain.
  • DTLS is enough for chat bodies or files.
  • Pair now or onion QR invites are confidential.
  • ProVerif covers the git host, a CORS proxy, or a stolen device.
  • A self-authored or AI-authored review replaces a third-party audit.
  • Rust, a cascade stack, or library proofs make a stolen unlocked session safe.

FAQ sentence: Glitr aims to keep message content from the host. It does not hide that you chat. This report is a draft in-house review. The app is a demo. Do not put sensitive details in it.

Start of this folder: Security audit. Catalog: Findings. Leftover: Residual risk.