diff options
| author | Christophe Besson <cbesson@gmail.com> | 2026-09-30 17:26:59 +0200 |
|---|---|---|
| committer | Christophe Besson <cbesson@gmail.com> | 2026-09-30 17:26:59 +0200 |
| commit | d692db441680eef8969573047cf5da00cfb61362 (patch) | |
| tree | 4a67e4bd2a6421a154c706d2aeb8cc7bfd548187 /docs/playlists.md | |
| parent | b1ebcdeb9082457972c41a47e77494902335d262 (diff) | |
| download | meshbay-d692db441680eef8969573047cf5da00cfb61362.tar.gz | |
docs: state the pepper, MBK3, the desktop keyring and browser access as they are
Design §2.2-§3.7, §4, §5.6, §7.7, §8, §9.10 and the registers; protocol §7,
§7.1, §7.1a and §13; the user guide; CLAUDE.md's parity rule.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'docs/playlists.md')
| -rw-r--r-- | docs/playlists.md | 7 |
1 files changed, 7 insertions, 0 deletions
diff --git a/docs/playlists.md b/docs/playlists.md index c41c71f..f1f6b67 100644 --- a/docs/playlists.md +++ b/docs/playlists.md @@ -220,6 +220,13 @@ bundles. So: playlist_key = HKDF-SHA256(bundle_key_v2, info = "meshbay:playlists:v1") ``` +> **Superseded (0.17.0).** A key from the passphrase alone made every sealed +> blob an offline oracle for it on every node. The key is now +> `HKDF-SHA256(M, info = "meshbay:playlists:v2")`, where `M` folds in a pepper +> the hub holds, and a blob that does not open under it is overwritten with the +> local copy — `MESHBAY_DESIGN.md` §3.7 and §9.10. The rest of this section is +> the reasoning as it stood, and still holds for `M`. + Three consequences, each of which is a line of code somewhere: - **`deriveEncryptionKey` must return an HKDF handle as well as the AES-GCM |