this.me / Tests / Security
Change any byte of a protected blob or of an identity envelope and the kernel fails closed: reads return nothing without throwing, unlocks are rejected, and wrong data is never handed back as if it were right. Bad KDF parameters and passwords are refused before any expensive work starts.
Two small pieces the Node test imports from src/ because the bundle doesn't export them, and the byte-level helpers from tests/Security/helpers.ts.
Every tampering attempt made by the cases on this page, with what the kernel returned. Cases are numbered in file order.
Independent cryptographic review of the primitives themselves (HMAC-Keccak256 construction, PBKDF2 parameterization). This battery tests the implementation's behavior under adversarial input — tampering, truncation, format confusion, KDF bounds — not the abstract security of the chosen primitives. See crypto-tamper.test.ts's file comment for the explicit "roundtrip alone doesn't prove correctness" framing the task asked for.README §1, attack model and its limits · tests/Security/README.md
No rollback/freshness detection for branch ciphertext. An attacker with write access to encryptedBranches (model A/D) can replace a scope's current chunk with an OLDER, but still validly-authenticated, chunk from the same scope+secret+root — the AEAD tag still checks out (it was real ciphertext once), and the kernel has no monotonic counter/version to detect the rollback. Not defended against, not tested as passing, documented as a real open gap. …README §7, open gaps · tests/Security/README.md