Tor
Native path only, and only with the tor feature. Product page: Tor. Implementation: tor-core session.rs, glitr-client tor_native.rs, whatsup onion.rs.
The browser build does not run Arti. mint_onion_invite on wasm returns that onion pairing needs desktop or TUI.
What Tor is used for
| Path | What is proxied | What is not |
|---|---|---|
| Git HTTPS on native | SOCKS5h | Live WebRTC ICE/media |
| Onion chat / preferred live signaling | Arti hidden service duplex | Browser ICE to Google STUN |
| Web without Tor | Git / onion via glitrProxy to a linked native device | The browser’s own ICE |
GLITR-2026-003 — WebRTC ICE does not ride Tor
Medium · Confirmed
Per-contact prefs default tor+webrtc on. When both are on and a peer onion is known, git auto-signaling offers are skipped so onion can set up live faster than git mailbox SDP. ICE/STUN/media can still be direct (Live and WebRTC).
Residual. Do not describe “Tor on” as “live media is anonymous.”
GLITR-2026-005 — mobile Arti permissions
Low · Confirmed
On Android / iOS, tor-core sets dangerously_trust_everyone() on Arti storage permissions. Mobile is not a claimed hardened product path.
Pairing
on1: invites are plaintext (GLITR-2026-009). Hello Match/Store promotes the contact to active (GLITR-2026-019).
Fixes: Remediation. Catalog: Findings.
