Skip to main content

Assets and attackers

Research, not an audit
These pages are research and development and may not match the live app. Do not treat this as an audit. Shared for testing and demo only. Please use responsibly.

This page lists what Glitr tries to keep from an attacker, and who we treat as one. Platform gaps sit on Platforms. Path-specific rows sit on git, live, and Tor.

A row here is in scope for discussion. It is not a claim that the control is complete.

Assets​

AssetSensitivityIf it is lost
Message and file plaintextCriticalThe contact can read the thread; so can anyone who has the session keys
RSA private key and protocol secretsCriticalNew ciphertext to this profile can be opened; old ratchet state may follow
Protocol session (Signal + PQXDH)CriticalLater messages on that contact skip the handshake; one session is shared across git, WebRTC, and onion so the ratchet does not fork
Encryption passwordCriticalSealed mailbox documents open; see Devices and storage
Git host tokenHighThe holder can push, fetch, and often delete the mailbox repo
Device-merge snapshotHighAnother device can apply your contacts, sessions, and mailbox rows
Contact graph and profile idsMediumWho you talk to, and how often, becomes easier to infer
Live media (voice / video)HighA path observer who can see the media stream hears or sees the call
Hello / safety-number materialMediumIdentity checks become social engineering instead of a local compare

Public profile material (RSA public key, protocol bundles) is meant to be readable. Peers need it to encrypt the first message. That is coordination, not a leak of the recipient cascade.

Adversaries​

AdversaryCapabilityIn scope
Passive network observerSees volumes, timing, destinations, ICE candidatesYes
Active network attackerRewrites bits on paths that are not end-to-end protectedYes
Honest-but-curious git hostReads repo files, logs IPs, collaborators, and push/fetch timesYes
Malicious git hostServes altered public rows, drops mail, closes the repoYes
CORS proxy operatorSees browser git HTTP (web)Yes
STUN / ICE path observerSees reflexive addresses and that a live link is formingYes
Malicious peerSends malformed frames, presents the wrong hello keysYes
Compromised out-of-band channelReads or swaps a wu1: or on1: QR / paste bundleYes
Malicious CDN / service workerServes a trojaned web clientYes
Local device / extension / unlocked sessionReads memory, storage, or the running UIYes — as a residual, not as a claimed defense
Host policyThrottles, blocks, or closes a mailbox repo under terms of serviceYes

State-level resource is not a claimed product target. It is a reason the residual page tells you not to put sensitive details in a demo.

Trust on first use​

There is no global peer-ID PKI. A contact becomes Active after a profile fetch (git URL) or after a live hello (Pair now / onion).

  • Git URL: you typed or pasted the remote. Pending → Active is “their public profile fetched.”
  • Live: evaluate_hello compares hello keys to what you already stored. Store, Match, or Mismatch. Mismatch is a UI prompt, not an automatic accept.
  • A safety number is computed locally from both hello keys. It is never sent on the wire. A browser can verify it without linking Arti.

That is TOFU plus a compare, not authenticated identity in the Signal-app sense.

Two jobs, two attackers​

A model of one job is not a proof of the other.

AttackerRecipient cascadePassword at rest
Network / peer without your keysMitigated — payload is cascadedNot the job
Git host without your passwordMitigated for bodies in outbound / signaling (ciphertext to a contact)Mitigated for sealed folders
Git host with your passwordStill cannot open their inbox; can open your sealed documentsOpen
Stolen unlocked sessionOpenOpen

Formal verification of the libraries assumes a network attacker and honest endpoints. It does not model the host or the device. See the verification report.

STRIDE on this product​

Mapped onto Glitr, not onto a signaling broker. The older Enkrypted chapter used a different product (central-ish signaling, TURN, federated JS). This table is the git-mailbox messenger.

CategoryExample hereControlStatus
SpoofingFake profile on a remote you added; swapped wu1: bundleTOFU, hello match / mismatch, safety numberPartial — no global identity
TamperingBit flip on outbound ciphertext; altered public profileAEAD on the cascade; profile fetch + hello compareMitigated for cascaded bodies; Partial for unsigned public rows
Repudiation“I did not send that”Not a product claim. Deniability is layer-dependent inside the librariesOpen as a Glitr feature
Information disclosureHost sees activity; ICE leaks an IP; typing frame on the data channelCascade on bodies and file bytes; sealing on local docsPartial — metadata is expected
Denial of serviceHost closes the repo; flood the data channel; drop onion circuitGit is best-effort mail; live has no mailbox fallback on Pair now / onionPartial
Elevation of privilegeRemote frame calls a local-only route; proxy fetches an arbitrary hostLocal RequestSource on sensitive routes; git/onion proxy allowlistsDocumented — not an audit of every route

Next: Platforms — the same assets, four different surfaces.