Skip to content

History / Secure Mode

Revisions

  • Document originDepth and the duress-oracle rejection removal (v1.10.1) Secure-Mode.md: add originDepth floor semantics alongside visibleThroughDepth's ceiling; new Inbound Message Handling section explaining passSecurityControl's removal and the one accepted trade; matching Forensic Deniability bullet. Security-Properties.md: Duress PIN / decoy view moves from "static indistinguishability" (warning) to "static + live-protocol indistinguishability" (fixed) -- the live-protocol test this row's old caveat described is now closed. Threat-Model.md: moves the closed live-protocol test to "Protects Against"; replaces the old vague "ongoing hardening work" line under "Does Not Protect Against" with the two specific, narrower residuals that actually remain.

    @aibo-cora aibo-cora committed Aug 8, 2026
  • Correct visibleThroughDepth docs; soften duress-indistinguishability claims Secure-Mode.md described the pre-fix nil-based model and incorrectly said VaultEntry follows the same ceiling rule as contacts - it uses exact-match depth confinement instead, which is what actually prevents duress-created entries from leaking into the real vault. Security-Properties.md and Threat-Model.md asserted unqualified duress/ normal indistinguishability. That's only established for static, at-rest inspection; full indistinguishability under active, extended adversarial testing isn't guaranteed yet and is being worked on - stated as an honest limitation rather than an unqualified claim.

    @aibo-cora aibo-cora committed Aug 5, 2026
  • Remove border-crossing-specific language from Secure Mode overview

    @aibo-cora aibo-cora committed Aug 1, 2026
  • Add technical documentation wiki pages

    Yura Filatov committed Jun 27, 2026