this.me / Tests / Security

Isolation between Identities

Two identities can use the same paths, the same _ secret strings, even the same ciphertext bytes. Data encrypted under one identity root doesn't open under another. A copy of the snapshot, the envelope or the public rootId doesn't help without that identity's password. The owner restoring their own backup with their own password is recovery, and it works.

Every value below is computed right now, in this page, by the .me kernel. Nothing is pasted in. The cases are the ones in Typescript/tests/Security/isolation.test.ts, which runs with npm test (via npm run test:security).

RUNNINGLoading kernel…

Setup and helpers

Code the cases below call that isn't part of the kernel.

Show code

Who tries to open what

Every attempt made by the cases below, with what the kernel returned. Cases are numbered in file order.

fails closed, as the test expectsopens, as the test expectsdiffers from what the test expects

What this does not promise

Protection against an attacker who controls the unlocked process itself. If code runs inside a kernel that is already unlocked with the right branch secrets supplied, it can read whatever that session can read — that is not a bug, it's what "unlocked" means. root-lifecycle.test.ts's rotate-auth regression is the one place this line gets close: it closes a gap where a caller did not need to unlock at all, which is different from "the process is already unlocked."

README §1, attack model and its limits · tests/Security/README.md