Release Notes
Current version
Every file is a release asset in octetproof/octet-browser, under v1.3.0. All versions and their changelogs are on the releases page.
| Asset | What it is |
|---|---|
octet-collector.js |
The collector, as a script that defines the global octet. Serve it from your own origin. |
octet-collector.js.sri |
The Subresource Integrity hash of octet-collector.js, for the integrity attribute. |
octet-collector.mjs |
The collector as an ES module. |
octetproof-collector-1.3.0.tgz |
The collector as an npm package, @octetproof/collector, with TypeScript types. |
octet-edge-linux-amd64 |
The edge, for Linux on x86-64. |
octet-edge-linux-arm64 |
The edge, for Linux on 64-bit ARM. |
SHA256SUMS |
SHA-256 checksums of the files above. |
SHA256SUMS.sig, SHA256SUMS.pem |
The cosign signature over SHA256SUMS, and its certificate. |
Use the collector and the edge from the same release. To check your downloads, see Deploy the Edge.
Collector support
Octet accepts collections from a collector release for 12 months after the release that replaces it. When a new release comes out, its entry below gives the date the previous collector stops being accepted. After that date, the old collector's sessions get 400 with unknown_seal_key.
Browser support
The collector is built for ECMAScript 2020, which every current version of Chrome, Edge, Firefox and Safari supports, on desktop and mobile. It needs fetch and a secure (HTTPS) page. In browsers that lack WebRTC or WebSockets, or where they are turned off, the collector still works and the verdict is weaker.
v1.3.0
Breaking: update the collector and the edge together. From this release, Octet accepts only sealed collections and only edges with a client certificate. A v1.2.0 collector gets 400 with unsealed_bundle, and a v1.2.0 edge without a client certificate gets 401 with client_cert_required. The v1.2.0 collector is not covered by the 12-month support window, because it doesn't seal its collections.
- The collector encrypts each collection to Octet before it leaves the browser. Your edge forwards it without being able to read it, and Octet can tell if it was changed on the way. See Integrity and Audit.
- Octet refuses a copy of a collection it accepted recently, through any edge, with
409andreplayed_bundle. - The collector keeps a device key in the browser's IndexedDB, in a database named
octeton your origin. See Privacy and Data. - The collector needs a secure (HTTPS) page. On a plain
http://page it fails at once with a clear error. - The published collector files are scrambled, which makes them harder to read. It doesn't make the collector's data trustworthy. The script is about 100 KB, or about 36 KB gzipped, and still needs no
unsafe-eval. - The edge connects to Octet only over mutual TLS, with a client certificate for your license. It refuses to start without one. You issue the certificate yourself in your license's Edge certificates tab in the Octet portal, and can revoke a single certificate there. See Deploy the Edge.
- New reason codes:
client_cert_required,client_cert_licence_mismatch,client_cert_revoked,unsealed_bundle,unknown_seal_key,bad_sealandreplayed_bundle. See Errors. - Octet uses only network timings that Octet's servers or your edge measure.
- Sessions through iCloud Private Relay keep the user's own country, and aren't treated as masked.
- In
fullmode,ready()can take up to about 4.5 s on a connection tunnelled to an exit far from the user. - New pages: Integrity and Audit and Keep Verdicts for Audit.
v1.2.0
The first public release of Octet Browser.
- The collector's
start()andready()split collection from the moment of action: start at page load, and wait at the moment of action. - Three collection modes,
full,liteandpassive. Every host the collector contacts is run by you or by Octet. - Each verdict carries a signed token, verifiable against Octet's published key set.
- Per-license read tokens for fetching verdicts, created and revoked by you in the Octet portal.
- The edge terminates TLS itself, and returns Octet's status and reason code when Octet refuses a session.
- Static edge binaries for Linux on
amd64andarm64. - The collector starts a Web Worker from a
blob:URL. Allowworker-src blob:in your Content Security Policy for the best results. See Network and CSP.