Documents
What the program does with your trust, written for people who want to check rather than believe.
Read first
- Security overview — the trust architecture in plain language: identities, verification words, session keys, the unattended password, accounts, the address book, updates, abuse.
- Threat model — the engineering document: assets, actors, every mechanism as built, and what each actor gets. Revised at each milestone that adds an actor.
Reference
- Protocol — the messages between the app and the broker, between two apps, and inside a session, as they are on the wire. Licensed CC BY 4.0 so anyone may implement or audit it.
- Windows 7 build — what the native build for Windows 7, 8 and 8.1 needs and how it differs.
- Signing — what the code signature and the update signature prove, and the state of the certificate.