Skip to content

Say what the verification, erasure and sealed claims actually establish - #225

Merged
404SecNotFound merged 2 commits into
mainfrom
claude/serene-carson-0739mv-assurance-language
Sep 28, 2026
Merged

404SecNotFound merged 2 commits into
mainfrom
claude/serene-carson-0739mv-assurance-language

Conversation

@404SecNotFound

@404SecNotFound 404SecNotFound commented Sep 27, 2026 •

Copy link
Copy Markdown
Owner

Summary

The assurance language is corrected where it claimed more than the code or the evidence supports, and a brief for a review of the current format is added. A sweep of every doc and UI string found about 60 assurance claims. Each change below was checked against the source before editing. Based on main. It refers to roadmap 9.x, which #223 adds, but does not conflict with #223 or #224.

Changes

Claims corrected

Where Said Now says
Docs guide, verify-only diagram the plaintext is discarded in the worker it comes back to the page, which zeroes it unshown (9.2)
SECURITY-AUDIT.md, roadmap 2.1 passwords and plaintext live in the worker's heap derived keys do; a dated correction says what crosses
Roadmap 2.3 authenticating AEAD requires producing the plaintext the tags need only the ciphertext, but the APIs the app calls verify by decrypting
Auto-lock toasts, dice tool secrets "wiped from memory", "clear the log from memory" cleared from the page
Sealed status label "nothing leaves" "no connections", which is what the policy check proves
In-place build check "N of N cached files match", silently skipping files not cached also says how many of the manifest's files were not checked, and that a manifest from the same place shows consistency, not origin
Verify page, VERIFYING.md, HOW-IT-WORKS.md, README verification proves "the bytes you ran" match; sha256sum checks the signature; "the audit" says whether the source is right the files you downloaded; the signature needs an identity from outside the site; the review on record does not cover the current format
Inspector "a removed slot can't hide" "a change made without a key is reported" (a slot holder can re-seal the table)
Page metadata keyword "zero knowledge" removed, as OUTREACH.md already rules out

SECURITY-AUDIT.md keeps its record and gains a dated correction note, not a silent rewrite. It still names none of the current-format subjects, so the README gate's scope check holds.

New: docs/AUDIT-BRIEF.md. It sets out what a reviewer of the current format needs:

  • the scope, pointing at the normative sections;
  • what is out of scope;
  • each adversary, with the documented position or an explicit question;
  • the evidence and its counts;
  • the open findings;
  • questions for the reviewer;
  • a claim register linking each security claim to its evidence and to what it rests on.

Needs an owner decision

The repository describes its reviews two ways.

  • SECURITY-AUDIT.md calls its findings "external review", and one section a "Third-party audit (four-agent swarm)".
  • OUTREACH.md says the project is "Not audited" and has a self-audit.
  • The README says parts of the current format have been through "external review passes".

Only you know who performed them. The brief states the conflict and asks readers not to treat those findings as independent assurance until you settle it. I did not change the audit's or the README's characterisation.

Test plan

  • typecheck, test:readme, test:release-notes, test:release-gate, test:release-recipe, test:seal-verdict and test:csp-egress pass.
  • tests/browser/sealed-status.spec.ts now checks the unchecked-file count against the manifest on disk. On the real build the manifest lists files the cache does not hold, so that branch is exercised. It also checks the origin caveat.
  • Negative controls, each typechecked and built before its result was read, with files restored and checked by checksum. Hiding the unchecked-file count fails the test ("the result hid the files it did not check"). Dropping the origin caveat fails it too.
  • Chromium full suite: 310 passed, 5 skipped, exit 0.
  • Firefox and WebKit run in this PR's CI.

Not done here

docs/AUDIT-BRIEF.md gathers what an external reviewer of the current
format needs: scope with pointers to the normative sections, what is
out of scope, adversaries with the documented position on each, the
evidence available, the open findings, questions for the reviewer, and
a claim register linking each security claim to its evidence and to
what it rests on. It says plainly that no review of the current format
has been engaged.

Roadmap 2.3 said authenticating an AEAD ciphertext requires producing
the plaintext, and that the verify-only plaintext stays in the worker
heap. The first is a property of the APIs the app calls, not of AES-GCM
or ChaCha20-Poly1305. The second is false: the worker returns the
plaintext to the page, which zeroes it (9.2).
The assurance wording is corrected where it claimed more than the code
or the evidence does. Each change was checked against the source first.

- Verify-only: the docs guide said the plaintext is discarded in the
  worker. It comes back to the page, which zeroes it without rendering
  it (9.2). SECURITY-AUDIT.md and roadmap 2.1 said passwords and
  plaintext live in the worker's heap; both now carry a dated correction.
- Erasure: the auto-lock toasts said secrets were "wiped from memory",
  and the dice tool offered to "clear the log from memory". JavaScript
  gives no such guarantee; they now say cleared from the page.
- Sealed status: "nothing leaves" became "no connections", which is
  what the policy check proves (SEALED_CLAIM already says blocking
  connections is not every way out). The in-place check said "N of N
  cached files match" without saying that files not in the cache are
  skipped; it now says how many of the manifest's files were not
  checked, and that a manifest from the same place shows consistency,
  not origin. The docs guide's "forbids every network destination" is
  narrowed the same way.
- Verification: the verify page, VERIFYING.md, HOW-IT-WORKS.md and the
  README said verification proves "the bytes you ran" match the source,
  or that sha256sum checks the signature. It checks the files you
  downloaded, and the signature needs an identity from outside the site.
  They also pointed at "the audit" for whether the source is correct;
  the review on record does not cover the current format.
- The inspector said "a removed slot can't hide"; a slot holder can
  re-seal the table, so it now says a change made without a key is
  reported.
- The "zero knowledge" metadata keyword is removed; OUTREACH.md already
  rules the phrase out.

The review brief now states that the repository describes its reviews
two ways (external review in SECURITY-AUDIT.md, a self-audit in
OUTREACH.md) and leaves which is right to the owner.

The sealed-status browser test now checks the unchecked-file count
against the manifest on disk, and the origin caveat. Negative controls:
hiding the count and dropping the caveat each fail it.
@404SecNotFound
404SecNotFound merged commit 2cbb640 into main Sep 28, 2026
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant