Sign inSign up

icyzip/e2ee-review

By icyzip

•Updated 3 days ago

Self-contained offline test lab for auditing IcyZip's open-source E2E encryption.

Image
0

145

icyzip/e2ee-review repository overview

⁠IcyZip E2EE review lab

This public multi-platform image packages IcyZip's standalone open-source browser E2EE protocol, synthetic tests, deterministic mutation fuzzing and practical inspection tools. It contains no relay or application-server source, opens no listening port and needs no network for its default run.

Platforms: linux/amd64 and linux/arm64/v8.

⁠Verify the exact release

IMAGE=docker.io/icyzip/e2ee-review@sha256:827fa29a1b1f98c7dac1df1b068ef7eac1113908876acfcffc5658ac70c4a75f
docker pull "$IMAGE"
docker run --rm --network=none --read-only --cap-drop=ALL \
  --security-opt=no-new-privileges --memory=768m --pids-limit=128 \
  --tmpfs /tmp:rw,nosuid,nodev,size=128m "$IMAGE"

The tags 0.4.0, 0.4 and latest currently resolve to that same multi-platform digest.

⁠What the default run checks

  • source, E2EE module, Node and OpenSSL identities;
  • the embedded SPDX inventory and retained license paths;
  • minimal exchange, cryptographic, receive-controller, security-regression, provenance and container-contract tests;
  • 256 deterministic mutations of authenticated keys, encrypted text and metadata, encrypted file frames, signed offers and pairing-link fragments;
  • legitimate text and file traffic still works after every rejected mutation.

All inputs are synthetic. The default run is unprivileged, read-only and offline when invoked with the flags above.

⁠Inspect and extend

The image includes node, npm, git, openssl, python3, jq, rg, file, od and strace.

docker run --rm --network=none icyzip/e2ee-review:0.4.0 npm run coverage
docker run --rm --network=none icyzip/e2ee-review:0.4.0 node tools/inspect.mjs
docker run --rm --network=none icyzip/e2ee-review:0.4.0 \
  node tools/fuzz.mjs --seed 4294967295 --iterations 10000

The full source, standalone Git repository, build recipe, threat model, test guide and security-reporting instructions are available at icyzip.com/open-source⁠.

⁠Security boundary

A passing run establishes only that the published checks passed for that image and input set. It is not proof that the protocol, browser delivery path, proprietary relay or hosted service has no weakness. Please report a suspected weakness through the private channel linked from the source page; ordinary feedback can be sent without giving an email address at icyzip.com/contact⁠.

Tag summary

Content type

Image

Digest

sha256:827fa29a1…

Size

154 MB

Last updated

3 days ago

docker pull icyzip/e2ee-review