Skip to content

feat(secure): group E2EE with Sender Keys, CodeQL hardening, and security audit settings - #17

Merged
NightSommelier merged 8 commits into
devfrom
feature/security-audit-and-privacy-hardening
Oct 7, 2026
Merged

NightSommelier merged 8 commits into
devfrom
feature/security-audit-and-privacy-hardening

Conversation

@NightSommelier

Copy link
Copy Markdown
Owner

Summary

This pull request introduces end-to-end encryption (E2EE) for group chats powered by Signal Sender Keys, resolves all open CodeQL security vulnerabilities in SecureOverlay, adds a device & app security audit checklist in settings, and hardens carrier UX.

Key Features & Changes

  1. Group Chat E2EE (Signal Sender Keys):

    • Implemented KeystoreSignalProtocolStore support for SenderKeyStore (GroupCipher, GroupSessionBuilder).
    • Added automatic sender key distribution and retry mechanisms.
    • Added group header UI indicators (lock indicator, member key status).
    • Added authenticated remote deletion of group messages via protocol control packets.
    • Added sender key rotation (manual via menu + automatic on member kick/leave).
    • Added auto-pairing for non-paired group members on incoming sender keys.
    • Enforced FLAG_SECURE screen capture protection for protected groups.
  2. CodeQL & Security Hardening:

    • Eliminated all 7 java/path-injection alerts in SecureMediaCrypto.java:
      • Added strict directory traversal validation (requireSafeFile).
      • Added safe temporary file allocation (createSafeTemporaryFile).
      • Covered by negative path traversal tests in SecureMediaCryptoTest.
  3. Security & Privacy Audit Checklist:

    • Added an interactive audit checklist in ForkSecureSettingsActivity:
      • App Passcode Lock check (clickable, links to PasscodeActivity).
      • USB Debugging (ADB) active state warning on physical access.
      • Screen capture protection (FLAG_SECURE) status.
      • Anti-phishing link guard status.
    • Full localization in Ukrainian and English.
  4. Fail-Closed Carrier Feedback:

    • Display informative bulletin when reactions are attempted on protected messages.
  5. Build & Version Display:

    • Detailed build version and git commit hash display with clipboard copy in settings.

Verification

  • Instrumentation Tests: 98/98 passed on physical device (CPH2581, Android 16) (./gradlew :SecureOverlay:connectedDebugAndroidTest).
  • Build Verification: Clean arm64 debug APK assembly via ./scripts/build-local-mvp.sh.
  • Device Verification: Streamed install and runtime check on physical device.

@NightSommelier
NightSommelier merged commit 21c20c1 into dev Oct 7, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant