Files
chanora/docs/security/threat-model.md
T
EdisonJwa f1bc9a6c85 chore(repo): initial baseline import (docs v0.9.2 + bootstrap)
Imports the v0.9.2 documentation baseline and the bootstrap files
required by docs/governance/repository-bootstrap-plan.md v0.1.0 §3,
minus the justfile (added in the next commit).

This commit establishes the git history for the project. All previous
work lived only as filesystem state with no version control.
2026-05-14 12:25:33 +08:00

7.3 KiB

Sec Threat Model V0.9.2.2.1

Document type: Security / Threat Model
Version: 0.9.2
Status: Baseline Candidate
Language: English
Product: Chanora
Repo path: docs/security/threat-model.md ---

1. Purpose

This document identifies Chanora security assets, trust boundaries, attack surfaces, threat scenarios, mitigations, and residual risks.

This document must be completed and approved before public or external release.

2. Security Scope

In scope:

  • Identity private keys and identity material
  • Server passwords
  • Saved bookmarks and recent server entries
  • Local database
  • Secure storage
  • Diagnostic logs and export bundles
  • Protocol input from compatible servers
  • Text messages, channel names, server names, and nicknames
  • Audio device access and microphone permission
  • Platform permission flows
  • Dependency and supply-chain risks
  • Flutter/Rust bridge boundary
  • Local file export/import surfaces

Out of scope unless later added:

  • Cloud account sync
  • Server hosting infrastructure operated by Chanora
  • Telemetry backend
  • Crash reporting backend
  • Payment processing

3. Assets

Asset ID Asset Sensitivity Required protection
SEC-ASSET-001 Identity private key / identity secret Critical Store only in platform secure storage; never log.
SEC-ASSET-002 Server password Critical Store only in platform secure storage; redact from diagnostics.
SEC-ASSET-003 Server address / bookmark Sensitive Store locally; redact or minimize in diagnostic export.
SEC-ASSET-004 Nickname / user identity display name Personal / user-provided Preserve Unicode; avoid unnecessary upload.
SEC-ASSET-005 Channel names and server names Potentially sensitive Treat as user/server content; redact where configured.
SEC-ASSET-006 Chat text Sensitive user/server content Do not upload automatically; redact from diagnostics by default unless user explicitly includes.
SEC-ASSET-007 Diagnostic bundle Sensitive aggregate Redact secrets; user-initiated export only.
SEC-ASSET-008 Local database Sensitive Protect via OS file permissions; avoid plaintext secrets.
SEC-ASSET-009 Logs Sensitive Redact secrets and avoid verbose sensitive content.
SEC-ASSET-010 Audio stream Sensitive real-time data Do not persist audio unless explicitly designed later.
SEC-ASSET-011 Dependency graph Supply-chain-sensitive Track licenses, vulnerabilities, and source integrity.

4. Trust Boundaries

Boundary ID Boundary Risk
TB-001 User input to Flutter UI Malformed or hostile input.
TB-002 Flutter to Rust bridge DTO validation and error mapping required.
TB-003 Rust Core to protocol adapter Protocol events and external inputs must be normalized.
TB-004 Protocol adapter to external compatible server Untrusted network/server input.
TB-005 Rust/Flutter to platform secure storage Platform-specific failure modes.
TB-006 App to local database/file system File tampering, data leakage, permissions.
TB-007 Diagnostics export to user-controlled destination Sensitive data leakage.
TB-008 Audio device boundary Permission and device-route privacy.
TB-009 Dependency supply chain Vulnerable or malicious dependencies.

5. Attack Surfaces

Surface ID Attack surface Example threats
AS-001 Connection form Credential capture in logs, malformed host input.
AS-002 Protocol input Malformed packets, hostile names/messages, state desync.
AS-003 Bridge DTOs Invalid commands, unexpected event payloads.
AS-004 Local database Tampering, unauthorized read.
AS-005 Secure storage Platform fallback failure or incorrect secret classification.
AS-006 Diagnostics export Secret leakage, excessive server/user information.
AS-007 Logs Password or identity leakage.
AS-008 Audio permissions Unclear microphone use or unintended capture.
AS-009 Dependency ecosystem Vulnerable packages or license incompatibility.
AS-010 Store/package distribution Tampered artifacts or signing issues.

6. Threat Scenarios and Mitigations

Threat ID Scenario Impact Mitigation Verification
THR-001 Server password is logged during connection failure. Credential leakage. Redaction filters; never log secret fields. Diagnostic redaction audit.
THR-002 Identity private key is stored in local DB. Identity compromise. Secure storage classification and audit. Secure storage audit.
THR-003 Diagnostic export includes server password or identity secret. Credential leakage. Export redaction and denylist/allowlist design. Redaction audit.
THR-004 Hostile server sends malformed Unicode or extremely long names. Crash, UI corruption, log injection. Boundary validation, length limits, safe rendering. Protocol fuzz/sanitization tests.
THR-005 Protocol event causes inconsistent UI state. Wrong user/channel state. State reducer validation and snapshot recovery. SWE.5/SWE.6 tests.
THR-006 Dependency has known critical vulnerability. Compromise or exploit risk. Dependency scan and release gate. Supply-chain report.
THR-007 OSS license is incompatible with release model. Legal/compliance risk. License inventory and legal review. Dependency/license report.
THR-008 Microphone permission is unclear to user. Privacy risk. Permission explanation and privacy policy. Privacy/legal review.
THR-009 Logs contain private channel or nickname data by default. Privacy leakage. Minimize logs; redact or hash sensitive content. Diagnostics audit.
THR-010 Build artifact is not traceable to commit. Supply-chain/release integrity risk. Release record with commit, tag, build number, hashes. Go/No-Go record.

7. Residual Risks

Risk ID Risk Disposition
RISK-001 External compatible servers may expose untrusted content. Accept with boundary validation and safe rendering.
RISK-002 Platform secure storage behavior differs by OS/version. Mitigate with per-platform audit.
RISK-003 Dependency vulnerabilities may appear after release. Mitigate with recurring scan and patch policy.
RISK-004 Diagnostic bundles may contain contextual sensitive data even after redaction. Mitigate with user confirmation and privacy notice.

8. Approval

Role Name Decision Date
Security Reviewer TBD Pending TBD
Software Architect TBD Pending TBD
Platform Owner TBD Pending TBD
QA / Verification Owner TBD Pending TBD

9. Change History

Version Date Description
0.9.0 2026-05-14 Initial threat model template and baseline candidate.

Baseline Candidate 0.9.1 Update

Version Date Description
0.9.1 2026-05-14 Updated baseline after product decision closure: Apple App Store SDK gate uses Xcode 26+ and iOS 26 / iPadOS 26 SDK+ since 2026-04-28, platform baselines and decision traceability propagated across the document set.

Baseline Candidate 0.9.2 Update

Version Date Description
0.9.2 2026-05-14 Corrected Apple App Store Connect upload gate to 2026-04-28 and checked full-package naming, references, and coverage.