aboutsummaryrefslogtreecommitdiffstats
path: root/docs/playlists.md
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-09-30 17:26:59 +0200
committerChristophe Besson <cbesson@gmail.com>2026-09-30 17:26:59 +0200
commitd692db441680eef8969573047cf5da00cfb61362 (patch)
tree4a67e4bd2a6421a154c706d2aeb8cc7bfd548187 /docs/playlists.md
parentb1ebcdeb9082457972c41a47e77494902335d262 (diff)
downloadmeshbay-d692db441680eef8969573047cf5da00cfb61362.tar.gz
docs: state the pepper, MBK3, the desktop keyring and browser access as they are
Design §2.2-§3.7, §4, §5.6, §7.7, §8, §9.10 and the registers; protocol §7, §7.1, §7.1a and §13; the user guide; CLAUDE.md's parity rule. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'docs/playlists.md')
-rw-r--r--docs/playlists.md7
1 files changed, 7 insertions, 0 deletions
diff --git a/docs/playlists.md b/docs/playlists.md
index c41c71f..f1f6b67 100644
--- a/docs/playlists.md
+++ b/docs/playlists.md
@@ -220,6 +220,13 @@ bundles. So:
playlist_key = HKDF-SHA256(bundle_key_v2, info = "meshbay:playlists:v1")
```
+> **Superseded (0.17.0).** A key from the passphrase alone made every sealed
+> blob an offline oracle for it on every node. The key is now
+> `HKDF-SHA256(M, info = "meshbay:playlists:v2")`, where `M` folds in a pepper
+> the hub holds, and a blob that does not open under it is overwritten with the
+> local copy — `MESHBAY_DESIGN.md` §3.7 and §9.10. The rest of this section is
+> the reasoning as it stood, and still holds for `M`.
+
Three consequences, each of which is a line of code somewhere:
- **`deriveEncryptionKey` must return an HKDF handle as well as the AES-GCM