Security Threat Model
This threat model defines the security goals, adversaries considered, trust assumptions, and explicit limitations of SecurityNet’s design.
SecurityNet is designed to protect the confidentiality and integrity of communications between explicitly authorised participants.
This document outlines:
SecurityNet prioritises controlled, private communication between trusted participants without relying on cloud communication infrastructure.
1. Scope & Security Objectives
Primary Objective
To ensure that:
Security Goals
SecurityNet is designed so that:
SecurityNet assumes a default-deny model: communication must be explicitly permitted.
2. Assets Protected
SecurityNet is designed to protect the following assets:
Message and file contents, together with their encryption passwords, are not stored centrally. Permission and identity information required to establish authorised connections is handled separately from communication content.
SecurityNet ID Records
SecurityNet stores limited identity and licensing information required to operate the service:
Central SecurityNet systems do not store:
The SecurityNet ID is stored in encrypted form and is not transmitted as part of communication sessions.
3. Adversaries Considered
SecurityNet is designed to protect against:
Network-Level Observers
These entities may observe that encrypted traffic is taking place, together with ordinary network-level information such as IP addresses, timing and data volume, but cannot read the encrypted communication content.
Mediator Infrastructure Operators
SecurityNet uses a lightweight mediator to introduce trusted devices. The mediator facilitates connection establishment between authorised devices but does not store message or file content.
The mediator server:
The mediator does not:
All encryption and decryption occur on endpoint devices.
Unauthorised Users
SecurityNet prevents connection attempts without:
There is no public discovery mechanism.
4. Threats Explicitly NOT Mitigated
SecurityNet does not claim to protect against:
If an endpoint is compromised, SecurityNet cannot guarantee confidentiality.
5. Trust Assumptions
SecurityNet relies on the following assumptions:
SecurityNet is not anonymous-by-default. It is private-by-design within controlled networks.
6. Network Visibility & Traffic Analysis
External network observers may be able to see:
They cannot see from the encrypted SecurityNet traffic:
SecurityNet communication is encrypted and carried within standard TLS traffic.
Users requiring additional destination privacy may choose to use a VPN or privacy network as part of their broader network configuration.
7. Architectural Boundaries
SecurityNet separates responsibilities:
Encrypted content never passes through or is stored by the website infrastructure.
The mediator facilitates connection establishment between authorised devices and does not store communication content.
All content encryption and decryption occurs on endpoint devices.
8. Design Philosophy
SecurityNet is not:
It is a controlled, encrypted communication environment built around trusted participants and peer-to-peer connections where possible.
SecurityNet minimises central infrastructure to reduce attack surface.