Security

Threat model

Which adversaries MYTHASE is designed to resist, and what it assumes.

A privacy system is only as meaningful as its threat model. This page states who we design against, so claims can be checked.

Adversaries

AdversaryCapabilityGoal of the design
Local observerWatches your Wi-Fi, ISP or workplace networkSees only encrypted, uniform traffic to a changing set of entry relays
Destination serviceSees incoming connections and requestsLearns neither your IP nor a persistent identity
Malicious relayRuns one or more relaysSees only adjacent hops; rotation limits how long it observes anyone
Infrastructure providerHosts some instancesInstances are stateless and short-lived; no stored data is readable
Network mapperScans and catalogues infrastructureMaps go stale every epoch
Partial global observerWatches large parts of the internetCorrelation is made harder and slower, not impossible

Assumptions

  • The user's device is not compromised.
  • Standard cryptographic primitives hold.
  • Not all relays on a path are controlled by the same adversary.
  • Users install genuine client software from official sources.

Review

Independent review of the infrastructure is a roadmap milestone before public release. Security reports can be sent to hello@mythase.xyz.