diff options
| author | Christophe Besson <cbesson@gmail.com> | 2026-10-01 12:05:12 +0200 |
|---|---|---|
| committer | Christophe Besson <cbesson@gmail.com> | 2026-10-01 12:05:12 +0200 |
| commit | 0d9d91eeea9001ea3838272416e3d526b6a2a1fc (patch) | |
| tree | 65aeb3efb4dea81d04c454c9c345b0df2949d9b7 /docs/MESHBAY_DESIGN.md | |
| parent | 760ac421b1944cd69a80e3a92127a1a966f15938 (diff) | |
| download | meshbay-0d9d91eeea9001ea3838272416e3d526b6a2a1fc.tar.gz | |
docs: chat at rest is protected from a copy without the unlock key, not from a disk
unlock.key sits beside keystore.enc by default, so a whole disk, an image or a
home-directory backup opens the stored chat. The claims table, §4.5 and the
user guide say so and name what protects those: disk encryption, or the unlock
key on other storage (F-20).
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'docs/MESHBAY_DESIGN.md')
| -rw-r--r-- | docs/MESHBAY_DESIGN.md | 14 |
1 files changed, 10 insertions, 4 deletions
diff --git a/docs/MESHBAY_DESIGN.md b/docs/MESHBAY_DESIGN.md index a43e35d..e721cb2 100644 --- a/docs/MESHBAY_DESIGN.md +++ b/docs/MESHBAY_DESIGN.md @@ -160,7 +160,7 @@ document uses: | File content is unreadable | ✅ | ❌ **T3** (browser) · ✅ native | ❌ by design — the operator hosts the files | ❌ members share the group key | ✅ | | The file index is unreadable | ✅ | ❌ T3 · ✅ native | ❌ | ❌ | ✅ | | Chat content is unreadable | ✅ | ❌ T3 · ✅ native | ❌ — the operator is a member | ❌ | ✅ | -| Chat is unreadable **off a stolen disk** | ✅ | ✅ | ✅ without the keystore passphrase | ✅ | ✅ | +| Chat is unreadable **from a copy of the node's storage that lacks its unlock key** — not from a whole disk by default (§4.5) | ✅ | ✅ | — the operator holds the unlock key | ✅ | ✅ | | Content cannot be modified | ✅ | ✅ | ❌ by design | ✅ | ✅ | | The node cannot be impersonated | ✅ | ✅ | — | ✅ | ✅ | | Client code integrity | ❌ **T3, accepted** (browser) · ✅ ships in the package (native) | ❌ T3 · ⚠️ native: **detectable, not prevented** | ✅ | ✅ | ✅ | @@ -919,9 +919,15 @@ where it stands on its own instead of pointing at a file to compare against. > requirement rather than from a module somebody left behind. **What chat encryption protects against, in the words the user-facing docs should -use:** someone who obtains the node's storage **without the keystore passphrase** — -a hosting provider imaging the machine, a leaked backup, a seizure where the -passphrase is not surrendered. It does **not** protect chat from the operator or +use:** someone who obtains the node's stored chat **without the key that unlocks +its keystore** — a backup of the data directory, a copy of the chat database. **By +default that key is not elsewhere:** setup writes `unlock.key` into the same +configuration directory as `keystore.enc`, so the whole disk, an image of the +machine or a backup of the home directory carries both, and opens. Against those +the protection is the disk's own encryption — BitLocker or Windows device +encryption, LUKS — or an unlock key kept off that disk (`[keystore] unlock_file` +on other storage, or `MESHBAY_UNLOCK_KEY` supplied from outside it; `node.env` +is in the same directory and is not outside it). It does **not** protect chat from the operator or any current member (they hold the group key, and the chat key is delivered under it); from anyone holding any one device of any member; from a former member, for messages sent before the epoch changed; from the hub as regards *metadata*; or |