aboutsummaryrefslogtreecommitdiffstats
path: root/docs/meshbay-draft-v5.md
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-08-13 14:32:47 +0200
committerChristophe Besson <cbesson@gmail.com>2026-08-13 14:32:47 +0200
commit38ad6c54f8c8a9180f0f7522dead38e57760d55e (patch)
tree9e842e7b72f34ec42263b20e84c5eb780c375a17 /docs/meshbay-draft-v5.md
parent8c5227365118383540a5e77b1885aef7e62bf6ec (diff)
downloadmeshbay-38ad6c54f8c8a9180f0f7522dead38e57760d55e.tar.gz
feat(client): pin node identities on first use — closes 11.5.8
The client verified the node's Ed25519 signature but did not remember which key it had seen, so a substituted node was caught only by its lack of the GEK. Trust On First Use: the node's public key is recorded per node_id on the first successful handshake and compared on every later one. A change is refused outright — strict, per operator decision. A warning users can click through is decorative, and this is the SSH known-hosts tradeoff taken deliberately. Scope, stated honestly: with C6 closed this is defence in depth, not the primary control. A substituted node already fails the GEK proof. Pinning covers the case where an attacker HAS the group key — an ex-member, or a leaked GEK — and swaps the node underneath, which the proof alone cannot distinguish from the real one. Strict refusal needs an escape hatch or it is a dead end: a node operator who reinstalls and loses their keystore generates a new pk_node and would otherwise lock out every member. Settings gains a "Node identities" section showing the pin count and clearing them, with copy telling the user to verify out of band first. Also exposed as MeshBayTransport.clearNodePin() for the native client. Tests: hub+common green; all five static JS files syntax-checked. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Diffstat (limited to 'docs/meshbay-draft-v5.md')
0 files changed, 0 insertions, 0 deletions