e2email-org / e2email

E2EMail is a simple Chrome application - a Gmail client that exchanges OpenPGP mail.

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Security audit

breznak opened this issue · comments

For such sensitive app, it would be almost crucial to perform a security audit (once a semi-stable version is reached)

As a good start, auditors shall refer to the "crypto heart" of this application and its threat model (look for the string mitiga to find out how they mitigate described attack vectors; some vectors might be though missing... thus the security audit).

The library received a few internal security reviews. The threat model posted above is a summary of the design level findings.