Skip to content

History

Revisions

  • Document originDepth and the duress-oracle rejection removal (v1.10.1) Secure-Mode.md: add originDepth floor semantics alongside visibleThroughDepth's ceiling; new Inbound Message Handling section explaining passSecurityControl's removal and the one accepted trade; matching Forensic Deniability bullet. Security-Properties.md: Duress PIN / decoy view moves from "static indistinguishability" (warning) to "static + live-protocol indistinguishability" (fixed) -- the live-protocol test this row's old caveat described is now closed. Threat-Model.md: moves the closed live-protocol test to "Protects Against"; replaces the old vague "ongoing hardening work" line under "Does Not Protect Against" with the two specific, narrower residuals that actually remain.

    @aibo-cora aibo-cora committed Aug 8, 2026
    dfe5edb
  • Correct visibleThroughDepth docs; soften duress-indistinguishability claims Secure-Mode.md described the pre-fix nil-based model and incorrectly said VaultEntry follows the same ceiling rule as contacts - it uses exact-match depth confinement instead, which is what actually prevents duress-created entries from leaking into the real vault. Security-Properties.md and Threat-Model.md asserted unqualified duress/ normal indistinguishability. That's only established for static, at-rest inspection; full indistinguishability under active, extended adversarial testing isn't guaranteed yet and is being worked on - stated as an honest limitation rather than an unqualified claim.

    @aibo-cora aibo-cora committed Aug 5, 2026
    94cb013
  • Remove border-crossing-specific language from Secure Mode overview

    @aibo-cora aibo-cora committed Aug 1, 2026
    228e1fe
  • Update Group Messaging wiki pages for v1.9.1 multi-layer duress + shard distribution The technical and overview pages still described the pre-Bug-73 binary real/duress member-list model (realMemberSlots/duressMemberSlots only) and didn't document the per-recipient vault shard distribution feature added in v1.9.1 (RecipientPayload's shardOperations/custodyManifest/expectedShards/ shardMetadataAttempted, the ShardPadding tiering scheme, and the fallback stripping on both send and receive).

    @aibo-cora aibo-cora committed Jul 4, 2026
    1ed9496
  • Update Group-Messaging-Technical: blind scheme, trial-decryption, corrected slot size - GroupEnvelope: replace cleartext id:UUID with blind/blindNonce/version fields (F-18) - Recipient: remove fingerprint/fingerprintNonce; slot-finding is now trial-decryption (F-20) - AAD: update outer and per-recipient formulas to use blind instead of groupID/fingerprint - Encrypt flow: remove fingerprint steps; add blindNonce/blind generation - Decrypt flow: replace fingerprint lookup with trial-decryption; add missingGroupID and senderProof steps - Slot size: correct 64 bytes → 156 bytes (128-byte padded plaintext + AES-GCM overhead) - Forensic trace: replace stale groupID correlation bullet with blind scheme properties

    @aibo-cora aibo-cora committed Jun 28, 2026
    36669b4
  • Add group messaging wiki pages

    Yura Filatov committed Jun 27, 2026
    3a99cdc
  • Remove test page

    Yura Filatov committed Jun 27, 2026
    c72c5c8
  • Add technical documentation wiki pages

    Yura Filatov committed Jun 27, 2026
    018de3b
  • Test page

    Yura Filatov committed Jun 27, 2026
    33dc8d9
  • Initial Home page

    @aibo-cora aibo-cora committed Jun 27, 2026
    c23e35a
  • Occulta vs Passkeys

    @aibo-cora aibo-cora committed Jun 27, 2026
    c14107a