Skip to main content

Residual risk

Research, not an audit
These pages are research and development and may not match the live app. Do not treat this as an audit. Shared for testing and demo only. Please use responsibly.

Even if every control on the earlier pages works as designed, Glitr does not become a finished, audited messenger. This page is the leftover, and the claims we will not make. The dated executive view — Glitr bar vs ideal-messenger gaps — is the report. This page stays the leftover catalog.

The app is shared for testing, feedback, and demo. Do not put sensitive details in it.

Non-goals​

ClaimWhy it is out
AnonymityRoadmap lists it. Product docs disclaim it. A host still sees activity, access, and IPs. Tor SOCKS changes the git IP, not the fact of a mailbox.
Signal-app compatibilityThe libraries are spec-faithful and educational. They are not wire-compatible with the Signal app.
Formal verification of the messengerFour libraries have tests, models, and stub type-checks. That does not compose into a proof of send, poll, git delivery, or a stolen host.
Safety against a compromised endpointMalware, a hostile OS, a browser extension, or an unlocked session reads what the app can read.
Safety against a host who has your passwordPassword sealing is one job. Handing the host the unlock secret ends that job.
Nation-state “safe forever”Not a product target. Closed-source and unaudited on purpose at this stage.

Residual list​

ResidualWhere it lives
Closed-source messenger; no independent auditThis site, the roadmap, the verification report
Unlock password and git tokens are not persisted in glitr:connect (GUI/TUI scrub)Devices and storage, GLITR-2026-013
User-supplied CORS proxy on the web git pathGit mailbox — no default public proxy
Public STUN and ICE IP leakage (per-contact STUN prefs; media still not over Tor)Live links, GLITR-2026-003
Plaintext wu1: / on1: invitesLive links, Tor
Live control frames (typing, receipts, call signaling) are DTLS-onlyLive links
Live WebRTC ICE/media does not ride Tor (signaling may prefer onion)Live links, Tor
Pair now / onion have no git fallbackLive links, Tor
Service worker + static host / GitHub Pages supply chain (isomorphic-git same-origin)Platforms (web), GLITR-2026-020
document::eval webview bridges (CSP allows unsafe-eval)Platforms (desktop / PWA)
Host metadata, collaborators, terms of serviceGit mailbox
Git cannot consume one-time prekeys like a prekey serverGit mailbox, data structures; pool + rotate exist (Cryptography)
Groups are fan-out on git onlyGit mailbox
Mobile and mobile-Tor are not claimed product pathsPlatforms, Tor
Side channels, compromised RNG, implementation bugsNot modeled. Not independently audited. In-house notes: Security audit

How this relates to formal verification​

Library pages use Tested / Modeled / Type-checked / Assumed / Open. This folder uses Documented / Mitigated / Partial / Open. The words are not interchangeable.

ProVerif in this stack is a Dolev–Yao network attacker plus honest endpoints and oracle primitives. The verification report attacker table says the host and the git mailbox are not modeled. Discussing them here does not put them in those models.

Cascade composition in crypto-cascade is a modeled layer order. It is not a proof of Glitr, git delivery, or a stolen laptop.

Audit status​

  • Independent security audit of the messenger: not done.
  • An in-house implementation review is on Security audit. It does not close the independent-audit row.
  • In-house or AI-authored notes are not a substitute. The roadmap FAQ says the same.
  • Signal Protocol source is public. ml-kem, pqxdh, mls, crypto, api, db, git, webrtc, tor, and the client are not. Cascade includes pairwise MLS per contact; groups use N-party GroupSession with per-member delivery seals (still git fan-out for transport).

If your threat model needs a reviewed, open messenger, this is the wrong app today.

Older writing​

An earlier Enkrypted chapter used a different product (signaling broker, TURN, federated modules). Do not copy those claims onto Glitr. The useful leftovers were the outline — adversaries, assets, scenarios, STRIDE, residual — not the rows.

The user-facing one-liner remains on encryption visibility.

Start of this folder: Threat model.