Skip to main content

Tor

Research, not an audit
These pages are research and development and may not match the live app. Do not treat this as an audit. Shared for testing and demo only. Please use responsibly.

Native path only, and only with the tor feature. Product page: Tor. Implementation: tor-core session.rs, glitr-client tor_native.rs, whatsup onion.rs.

The browser build does not run Arti. mint_onion_invite on wasm returns that onion pairing needs desktop or TUI.

What Tor is used for​

PathWhat is proxiedWhat is not
Git HTTPS on nativeSOCKS5hLive WebRTC ICE/media
Onion chat / preferred live signalingArti hidden service duplexBrowser ICE to Google STUN
Web without TorGit / onion via glitrProxy to a linked native deviceThe browser’s own ICE

GLITR-2026-003 — WebRTC ICE does not ride Tor​

Medium · Confirmed

Per-contact prefs default tor+webrtc on. When both are on and a peer onion is known, git auto-signaling offers are skipped so onion can set up live faster than git mailbox SDP. ICE/STUN/media can still be direct (Live and WebRTC).

Residual. Do not describe “Tor on” as “live media is anonymous.”

GLITR-2026-005 — mobile Arti permissions​

Low · Confirmed

On Android / iOS, tor-core sets dangerously_trust_everyone() on Arti storage permissions. Mobile is not a claimed hardened product path.

Pairing​

on1: invites are plaintext (GLITR-2026-009). Hello Match/Store promotes the contact to active (GLITR-2026-019).

Fixes: Remediation. Catalog: Findings.