aboutsummaryrefslogtreecommitdiffstats
path: root/docs/MESHBAY_DESIGN.md
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-09-28 15:48:04 +0200
committerChristophe Besson <cbesson@gmail.com>2026-09-28 15:48:04 +0200
commit5330896c0e8023053d4cd15961b2ae0482686ca6 (patch)
treee20b35069d4a7a87b1271e9063adb6a5c8e1b157 /docs/MESHBAY_DESIGN.md
parent0584daa4b77048712c42fa113e77efdd31fc0336 (diff)
downloadmeshbay-5330896c0e8023053d4cd15961b2ae0482686ca6.tar.gz
fix: refuse an unsigned handshake challenge
Every node the 4.0 floor admits signs its challenge, and one without a channel binding could not complete the proof anyway, so a missing signature is refused like a wrong one (browser and QUIC client). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'docs/MESHBAY_DESIGN.md')
-rw-r--r--docs/MESHBAY_DESIGN.md6
1 files changed, 3 insertions, 3 deletions
diff --git a/docs/MESHBAY_DESIGN.md b/docs/MESHBAY_DESIGN.md
index 170081f..74c1050 100644
--- a/docs/MESHBAY_DESIGN.md
+++ b/docs/MESHBAY_DESIGN.md
@@ -959,9 +959,9 @@ buys, per the convention at the top: a client that knows which node it means to
reach can refuse to send a code anywhere else — against a hijacked signaling path
and against a second host of the same group. It proves *a* key, not the *right*
one: it helps only a client that already knows which key to expect. A wrong
-signature is refused; an absent one leaves the key unproved until the ack, and a
-client holding a link code then does not send it. With the floor at 4.0 every
-reachable node signs, so that branch is one only a lowered floor could reach again.
+signature is refused, and so is an absent one: every node the floor admits signs
+whenever it has a channel binding, and one without a binding could not complete the
+proof anyway.
**Channel binding is mandatory and an absent one is refused** — never degraded to
nonce-only, which would silently drop MitM detection: