Assets and attackers
This page lists what Glitr tries to keep from an attacker, and who we treat as one. Platform gaps sit on Platforms. Path-specific rows sit on git, live, and Tor.
A row here is in scope for discussion. It is not a claim that the control is complete.
Assets
| Asset | Sensitivity | If it is lost |
|---|---|---|
| Message and file plaintext | Critical | The contact can read the thread; so can anyone who has the session keys |
| RSA private key and protocol secrets | Critical | New ciphertext to this profile can be opened; old ratchet state may follow |
| Protocol session (Signal + PQXDH) | Critical | Later messages on that contact skip the handshake; one session is shared across git, WebRTC, and onion so the ratchet does not fork |
| Encryption password | Critical | Sealed mailbox documents open; see Devices and storage |
| Git host token | High | The holder can push, fetch, and often delete the mailbox repo |
| Device-merge snapshot | High | Another device can apply your contacts, sessions, and mailbox rows |
| Contact graph and profile ids | Medium | Who you talk to, and how often, becomes easier to infer |
| Live media (voice / video) | High | A path observer who can see the media stream hears or sees the call |
| Hello / safety-number material | Medium | Identity checks become social engineering instead of a local compare |
Public profile material (RSA public key, protocol bundles) is meant to be readable. Peers need it to encrypt the first message. That is coordination, not a leak of the recipient cascade.
Adversaries
| Adversary | Capability | In scope |
|---|---|---|
| Passive network observer | Sees volumes, timing, destinations, ICE candidates | Yes |
| Active network attacker | Rewrites bits on paths that are not end-to-end protected | Yes |
| Honest-but-curious git host | Reads repo files, logs IPs, collaborators, and push/fetch times | Yes |
| Malicious git host | Serves altered public rows, drops mail, closes the repo | Yes |
| CORS proxy operator | Sees browser git HTTP (web) | Yes |
| STUN / ICE path observer | Sees reflexive addresses and that a live link is forming | Yes |
| Malicious peer | Sends malformed frames, presents the wrong hello keys | Yes |
| Compromised out-of-band channel | Reads or swaps a wu1: or on1: QR / paste bundle | Yes |
| Malicious CDN / service worker | Serves a trojaned web client | Yes |
| Local device / extension / unlocked session | Reads memory, storage, or the running UI | Yes — as a residual, not as a claimed defense |
| Host policy | Throttles, blocks, or closes a mailbox repo under terms of service | Yes |
State-level resource is not a claimed product target. It is a reason the residual page tells you not to put sensitive details in a demo.
Trust on first use
There is no global peer-ID PKI. A contact becomes Active after a profile fetch (git URL) or after a live hello (Pair now / onion).
- Git URL: you typed or pasted the remote. Pending → Active is “their public profile fetched.”
- Live:
evaluate_hellocompares hello keys to what you already stored. Store, Match, or Mismatch. Mismatch is a UI prompt, not an automatic accept. - A safety number is computed locally from both hello keys. It is never sent on the wire. A browser can verify it without linking Arti.
That is TOFU plus a compare, not authenticated identity in the Signal-app sense.
Two jobs, two attackers
A model of one job is not a proof of the other.
| Attacker | Recipient cascade | Password at rest |
|---|---|---|
| Network / peer without your keys | Mitigated — payload is cascaded | Not the job |
| Git host without your password | Mitigated for bodies in outbound / signaling (ciphertext to a contact) | Mitigated for sealed folders |
| Git host with your password | Still cannot open their inbox; can open your sealed documents | Open |
| Stolen unlocked session | Open | Open |
Formal verification of the libraries assumes a network attacker and honest endpoints. It does not model the host or the device. See the verification report.
STRIDE on this product
Mapped onto Glitr, not onto a signaling broker. The older Enkrypted chapter used a different product (central-ish signaling, TURN, federated JS). This table is the git-mailbox messenger.
| Category | Example here | Control | Status |
|---|---|---|---|
| Spoofing | Fake profile on a remote you added; swapped wu1: bundle | TOFU, hello match / mismatch, safety number | Partial — no global identity |
| Tampering | Bit flip on outbound ciphertext; altered public profile | AEAD on the cascade; profile fetch + hello compare | Mitigated for cascaded bodies; Partial for unsigned public rows |
| Repudiation | “I did not send that” | Not a product claim. Deniability is layer-dependent inside the libraries | Open as a Glitr feature |
| Information disclosure | Host sees activity; ICE leaks an IP; typing frame on the data channel | Cascade on bodies and file bytes; sealing on local docs | Partial — metadata is expected |
| Denial of service | Host closes the repo; flood the data channel; drop onion circuit | Git is best-effort mail; live has no mailbox fallback on Pair now / onion | Partial |
| Elevation of privilege | Remote frame calls a local-only route; proxy fetches an arbitrary host | Local RequestSource on sensitive routes; git/onion proxy allowlists | Documented — not an audit of every route |
Next: Platforms — the same assets, four different surfaces.
