Skip to content

docs(security): record device threat model and mitigations - #176

Merged
MaxDac merged 1 commit into
mainfrom
maxdac-device-threat-hardening
Oct 8, 2026
Merged

MaxDac merged 1 commit into
mainfrom
maxdac-device-threat-hardening

Conversation

@MaxDac

@MaxDac MaxDac commented Oct 8, 2026

Copy link
Copy Markdown
Owner

Adds a "Device threats" section to docs/security/e2ee-audit.md. It covers malicious apps on the user's phone, without root.

  • Server: no code change. The token is already encrypted on the phone with a key that can't be exported. A recovery-phrase takeover already shows up as identity_superseded.
  • App mitigations in PriveeApp: screenshots and screen recording blocked (FLAG_SECURE), other apps' overlays hidden, the screen hidden from accessibility apps that aren't real assistive tools, no keyboard learning, and notifications that say only "New message", with no sender.
  • Rejected options, and why: StrongBox, setUnlockedDeviceRequired, root detection, Play Integrity, clipboard flags and an app lock.

The matching app change is in a separate PriveeApp PR.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: c903ccbf-d878-4104-9946-cb6b1479b984
@MaxDac
MaxDac merged commit 225dd85 into main Oct 8, 2026
6 checks passed
@MaxDac
MaxDac deleted the maxdac-device-threat-hardening branch October 8, 2026 15:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant