aboutsummaryrefslogtreecommitdiffstats
path: root/docs/MESHBAY_DESIGN.md
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-10-01 12:05:12 +0200
committerChristophe Besson <cbesson@gmail.com>2026-10-01 12:05:12 +0200
commit0d9d91eeea9001ea3838272416e3d526b6a2a1fc (patch)
tree65aeb3efb4dea81d04c454c9c345b0df2949d9b7 /docs/MESHBAY_DESIGN.md
parent760ac421b1944cd69a80e3a92127a1a966f15938 (diff)
downloadmeshbay-0d9d91eeea9001ea3838272416e3d526b6a2a1fc.tar.gz
docs: chat at rest is protected from a copy without the unlock key, not from a disk
unlock.key sits beside keystore.enc by default, so a whole disk, an image or a home-directory backup opens the stored chat. The claims table, §4.5 and the user guide say so and name what protects those: disk encryption, or the unlock key on other storage (F-20). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'docs/MESHBAY_DESIGN.md')
-rw-r--r--docs/MESHBAY_DESIGN.md14
1 files changed, 10 insertions, 4 deletions
diff --git a/docs/MESHBAY_DESIGN.md b/docs/MESHBAY_DESIGN.md
index a43e35d..e721cb2 100644
--- a/docs/MESHBAY_DESIGN.md
+++ b/docs/MESHBAY_DESIGN.md
@@ -160,7 +160,7 @@ document uses:
| File content is unreadable | ✅ | ❌ **T3** (browser) · ✅ native | ❌ by design — the operator hosts the files | ❌ members share the group key | ✅ |
| The file index is unreadable | ✅ | ❌ T3 · ✅ native | ❌ | ❌ | ✅ |
| Chat content is unreadable | ✅ | ❌ T3 · ✅ native | ❌ — the operator is a member | ❌ | ✅ |
-| Chat is unreadable **off a stolen disk** | ✅ | ✅ | ✅ without the keystore passphrase | ✅ | ✅ |
+| Chat is unreadable **from a copy of the node's storage that lacks its unlock key** — not from a whole disk by default (§4.5) | ✅ | ✅ | — the operator holds the unlock key | ✅ | ✅ |
| Content cannot be modified | ✅ | ✅ | ❌ by design | ✅ | ✅ |
| The node cannot be impersonated | ✅ | ✅ | — | ✅ | ✅ |
| Client code integrity | ❌ **T3, accepted** (browser) · ✅ ships in the package (native) | ❌ T3 · ⚠️ native: **detectable, not prevented** | ✅ | ✅ | ✅ |
@@ -919,9 +919,15 @@ where it stands on its own instead of pointing at a file to compare against.
> requirement rather than from a module somebody left behind.
**What chat encryption protects against, in the words the user-facing docs should
-use:** someone who obtains the node's storage **without the keystore passphrase** —
-a hosting provider imaging the machine, a leaked backup, a seizure where the
-passphrase is not surrendered. It does **not** protect chat from the operator or
+use:** someone who obtains the node's stored chat **without the key that unlocks
+its keystore** — a backup of the data directory, a copy of the chat database. **By
+default that key is not elsewhere:** setup writes `unlock.key` into the same
+configuration directory as `keystore.enc`, so the whole disk, an image of the
+machine or a backup of the home directory carries both, and opens. Against those
+the protection is the disk's own encryption — BitLocker or Windows device
+encryption, LUKS — or an unlock key kept off that disk (`[keystore] unlock_file`
+on other storage, or `MESHBAY_UNLOCK_KEY` supplied from outside it; `node.env`
+is in the same directory and is not outside it). It does **not** protect chat from the operator or
any current member (they hold the group key, and the chat key is delivered under
it); from anyone holding any one device of any member; from a former member, for
messages sent before the epoch changed; from the hub as regards *metadata*; or