Security
Threat model
Which adversaries MYTHASE is designed to resist, and what it assumes.
A privacy system is only as meaningful as its threat model. This page states who we design against, so claims can be checked.
Adversaries
| Adversary | Capability | Goal of the design |
|---|---|---|
| Local observer | Watches your Wi-Fi, ISP or workplace network | Sees only encrypted, uniform traffic to a changing set of entry relays |
| Destination service | Sees incoming connections and requests | Learns neither your IP nor a persistent identity |
| Malicious relay | Runs one or more relays | Sees only adjacent hops; rotation limits how long it observes anyone |
| Infrastructure provider | Hosts some instances | Instances are stateless and short-lived; no stored data is readable |
| Network mapper | Scans and catalogues infrastructure | Maps go stale every epoch |
| Partial global observer | Watches large parts of the internet | Correlation is made harder and slower, not impossible |
Assumptions
- The user's device is not compromised.
- Standard cryptographic primitives hold.
- Not all relays on a path are controlled by the same adversary.
- Users install genuine client software from official sources.
Review
Independent review of the infrastructure is a roadmap milestone before public release. Security reports can be sent to hello@mythase.xyz.
