Version: 1.0 Last Updated: 2025-11-22 Status: Active
UbiCity is a privacy-first learning capture system. This threat model identifies security risks, threat actors, attack vectors, and mitigations to protect learner data and system integrity.
Primary Asset: Learning experience data (WHO/WHERE/WHAT) Security Goal: Confidentiality, integrity, availability of learner data
┌─────────────┐
│ Learner │ (captures experiences via CLI)
└──────┬──────┘
│
v
┌─────────────┐
│ CLI │ (/ runtime)
│ (src/*.ts) │
└──────┬──────┘
│
v
┌─────────────┐
│ Validator │ (Rust/WASM, )
│ (WASM) │
└──────┬──────┘
│
v
┌─────────────┐
│ Storage │ (Local JSON files)
│ (./data) │
└─────────────┘
Motivation: Access private learning data, modify experiences Capability: Filesystem access, command execution Likelihood: Medium Impact: High (privacy violation)
Motivation: Supply chain attack, data exfiltration Capability: Code execution during install/runtime Likelihood: Low (zero npm dependencies) Impact: Critical
Motivation: None (unintentional) Capability: User error (sharing private data) Likelihood: Medium Impact: Medium (privacy violation)
Threat: Malicious user reads private learning data Attack Vector: -
Direct filesystem access to ./ubicity-data/ - Memory dump while CLI
running - Shared computer access
Mitigations: - ✅ File permissions (user-only read/write) - ✅ No
cloud sync by default (local-only) - ✅ Privacy levels
(private/anonymous/public) -
Risk: MEDIUM → LOW (with mitigations)
Threat: Malicious modification of experiences Attack Vector: - Direct JSON file editing - CLI command injection - WASM validator bypass
Mitigations: - ✅ WASM validation (integrity checks) - ✅ permissions
(--allow-write limited to data dir) - ✅ compile-time checks -
Risk: LOW
Threat: Malicious dependency exfiltrates data Attack Vector: - Compromised npm package - Malicious module - Backdoored compiler
Mitigations: - ✅ ZERO npm dependencies (production) - ✅ JSR registry
(cryptographically signed) - ✅ Nix reproducible builds (pinned
dependencies) - ✅ GitLab CI verification on every commit - ✅
cargo audit for Rust dependencies
Risk: VERY LOW
Threat: Attacker executes arbitrary commands via CLI Attack Vector:
- Malicious input in description field - Filename injection
(../../etc/passwd) - Shell metacharacters
Mitigations: - ✅ sandboxing (explicit permissions) - ✅ Path
validation (no directory traversal) - ✅ Input sanitization (Zod
schemas) - ✅ No eval() or dynamic code execution
Risk: VERY LOW
Threat: User accidentally shares private data Attack Vector: - Exporting with private experiences included - Publishing dataset without anonymization - Sharing visualization with PII
Mitigations: - ✅ Privacy levels enforced in exports - ✅
Anonymization tools (hash IDs, fuzz location) - ✅ PII removal (emails,
phones) - ✅ Shareable dataset generator (excludes private) -
Risk: MEDIUM
Threat: WASM code escapes sandbox, accesses host system Attack Vector: - WASM exploit (CVE in ’s V8 engine) - Unsafe Rust code in WASM module
Mitigations: - ✅ WASM sandbox (linear memory isolation) - ✅ Zero
unsafe blocks in Rust code - ✅ cargo clippy enforces safety -
✅ auto-updates (security patches) -
Risk: VERY LOW
Threat: Malicious input causes CLI crash or hang Attack Vector: - Extremely large JSON files - Infinite loops in mapper logic - Memory exhaustion
Mitigations: - ✅ File size limits (implicit via memory) - ✅ Async
I/O (non-blocking) - ✅ WASM memory limits -
Risk: LOW
User Input → CLI → WASM Validator → JSON File
↓ ↓ ↓ ↓
[PII?] [Sanitize] [Validate] [Encrypt?]
Threats: - PII in description field → Mitigated by user control
anonymization tools - Path traversal in filename → Mitigated by path
validation
-
✅ explicit permissions (
--allow-read,--allow-write) -
✅ WASM sandboxing (linear memory isolation)
-
✅ Input validation (Zod + WASM validators)
-
✅ Zero npm dependencies (supply chain risk reduction)
-
✅ Offline-first (no network calls)
-
✅ Security audit script (
security/audit.sh) -
✅
cargo audit(Rust dependency CVEs) -
✅ Trivy filesystem scanner
-
✅ GitLab CI security checks
-
✅ Test suite (including security tests)
Sensitive Data: - Learner names, emails, phone numbers - Precise GPS coordinates (< 100m) - Demographic information
Mitigations: - ✅ Minimal data collection (WHO/WHERE/WHAT only) - ✅ Privacy by default (no demographic fields in schema) - ✅ Location fuzzing (round to ~1km) - ✅ Learner ID hashing (SHA-256) - ✅ PII removal tools (regex-based)
-
GDPR (EU): ✅ Data minimization, privacy by design
-
CCPA (California): ✅ User data ownership (local storage)
-
COPPA (US, children):
⚠️ Age-gated features (not implemented)
-
Encryption at rest (AES-256 for sensitive fields)
-
Cryptographic signatures (verify data integrity)
-
External security audit (penetration testing)
-
Bug bounty program (coordinated vulnerability disclosure)
-
Incident response plan (documented procedures)
Review Cadence: Quarterly or on major releases Owner: Maintainers
(see MAINTAINERS.md) Process: 1. Identify new features/changes 2.
Enumerate new threats 3. Assess risk (likelihood × impact) 4. Implement
mitigations 5. Update this document
Found a vulnerability? See .well-known/security.txt
-
Contact: security@ubicity.example.org
-
PGP Key: [Future: public key]
-
Disclosure Policy: 90-day coordinated disclosure
-
Bounty: No cash bounty (community project)
Document Classification: Public Version History: - v1.0 (2025-11-22): Initial threat model for Platinum RSR tier