this.me / Tests / Security

Replay and Restart

A kernel rebuilt from a snapshot comes back closed. Unlocking the identity alone doesn't reopen a protected scope; its secret has to be supplied again. Then everything comes back exactly, final values included, with no plaintext stored anywhere in between.

Every value below is computed right now, in this page, by the .me kernel. Nothing is pasted in. The cases are the ones in Typescript/tests/Security/replay-restart.test.ts, which runs with npm test (via npm run test:security).

RUNNINGLoading kernel…

Setup and helpers

Code the cases below call that isn't part of the kernel.

Show code

Before and after restart

Values read from the restarted kernel in the cases below. Cases are numbered in file order.

fails closed, as the test expectsopens, as the test expectsdiffers from what the test expects

What this does not promise

Rollback/staleness detection: can an attacker present old-but-genuine ciphertext as current? Not defended against or tested here — this kernel has no anti-replay/freshness mechanism for branch ciphertext (a scope's stored blob is just "the current value"; there is no monotonic counter or freshness proof). …

README §1, attack model and its limits · tests/Security/README.md