this.me / Tests / Security

Information Leakage

Protected values, scope secrets and passwords don't show up in anything that leaves the kernel: the snapshot, the memory log, error messages. Each case writes unique marker strings into a protected scope, then scans those surfaces for them.

Every value below is computed right now, in this page, by the .me kernel. Nothing is pasted in. The cases are the ones in Typescript/tests/Security/leakage.test.ts, which runs with npm test (via npm run test:security).

RUNNINGLoading kernel…

Setup and helpers

The scan helper from tests/Security/helpers.ts.

Show code

Where the markers were looked for

Every scan made by the cases below. Cases are numbered in file order.

What this does not promise

Metadata/traffic-analysis privacy. Scope-path keys, chunk counts, and ciphertext sizes are plaintext on disk by design (§3.6 of the doc). Nothing here tries to hide that a path exists, only its content and its _()/~() declaration value.

README §1, attack model and its limits · tests/Security/README.md