Document originDepth and the duress-oracle rejection removal (v1.10.1) Secure-Mode.md: add originDepth floor semantics alongside visibleThroughDepth's ceiling; new Inbound Message Handling section explaining passSecurityControl's removal and the one accepted trade; matching Forensic Deniability bullet. Security-Properties.md: Duress PIN / decoy view moves from "static indistinguishability" (warning) to "static + live-protocol indistinguishability" (fixed) -- the live-protocol test this row's old caveat described is now closed. Threat-Model.md: moves the closed live-protocol test to "Protects Against"; replaces the old vague "ongoing hardening work" line under "Does Not Protect Against" with the two specific, narrower residuals that actually remain.
Correct visibleThroughDepth docs; soften duress-indistinguishability claims Secure-Mode.md described the pre-fix nil-based model and incorrectly said VaultEntry follows the same ceiling rule as contacts - it uses exact-match depth confinement instead, which is what actually prevents duress-created entries from leaking into the real vault. Security-Properties.md and Threat-Model.md asserted unqualified duress/ normal indistinguishability. That's only established for static, at-rest inspection; full indistinguishability under active, extended adversarial testing isn't guaranteed yet and is being worked on - stated as an honest limitation rather than an unqualified claim.
Remove border-crossing-specific language from Secure Mode overview
Update Group Messaging wiki pages for v1.9.1 multi-layer duress + shard distribution The technical and overview pages still described the pre-Bug-73 binary real/duress member-list model (realMemberSlots/duressMemberSlots only) and didn't document the per-recipient vault shard distribution feature added in v1.9.1 (RecipientPayload's shardOperations/custodyManifest/expectedShards/ shardMetadataAttempted, the ShardPadding tiering scheme, and the fallback stripping on both send and receive).
Update Group-Messaging-Technical: blind scheme, trial-decryption, corrected slot size - GroupEnvelope: replace cleartext id:UUID with blind/blindNonce/version fields (F-18) - Recipient: remove fingerprint/fingerprintNonce; slot-finding is now trial-decryption (F-20) - AAD: update outer and per-recipient formulas to use blind instead of groupID/fingerprint - Encrypt flow: remove fingerprint steps; add blindNonce/blind generation - Decrypt flow: replace fingerprint lookup with trial-decryption; add missingGroupID and senderProof steps - Slot size: correct 64 bytes → 156 bytes (128-byte padded plaintext + AES-GCM overhead) - Forensic trace: replace stale groupID correlation bullet with blind scheme properties
Add group messaging wiki pages
Remove test page
Add technical documentation wiki pages
Test page
Initial Home page
Occulta vs Passkeys