diff options
| author | Christophe Besson <cbesson@gmail.com> | 2026-08-14 19:35:37 +0200 |
|---|---|---|
| committer | Christophe Besson <cbesson@gmail.com> | 2026-08-14 19:35:37 +0200 |
| commit | c83a4f6ab0c8a83e8679e78427ae60dc29bb2c60 (patch) | |
| tree | dea71c8e115742beaac5952c8c65481bbc130b07 /tmp-decisions.md | |
| parent | ee6573c57f721db8550e34e1c1c79c5922c62a4b (diff) | |
| parent | d324792d68503109ab99616af6c85ee37045e169 (diff) | |
| download | meshbay-c83a4f6ab0c8a83e8679e78427ae60dc29bb2c60.tar.gz | |
merge: Phase 11.5 security remediation, invite redesign, per-node identity
Brings in the security remediation branch. Three bodies of work, and what they
changed about what this project may claim.
Phase 11.5 closed the gap between the documents and the code: the unauthenticated
node HTTP API and the TCP transport deleted, one handshake shared by the
remaining two transports, mutual authentication, structured admin transcripts,
upload confinement, group isolation, revocation that reaches nodes. Six critical
and seven high findings closed, bounded, or deferred by decision.
The invite redesign closed H3 and M3 — the last open High. The hub was the key
directory: an inviter fetched the invitee's key from it and wrapped the group key
for whatever came back, so a hub answering with its own key was handed the group
key by an honest member following the protocol exactly. That lookup is gone. The
node holds the group key and wraps it itself, for a key its recipient proves
possession of, bound to an account by a one-time code the hub never sees. M3 fell
out of the same work: node authority comes from a local roster, never from the
hub.
Per-node identity cut what remains of C4 down to one operator. A single keypair
used to be copied to every node its owner joined; each node now gets its own, so
cracking the bundle on one machine yields a key that is a stranger everywhere
else — and on that machine, one that unlocks nothing its holder did not already
serve. The bundle KDF moved to Argon2id 128 MB, and the hub stopped storing or
publishing user keys at all.
What this project may now say: the hub cannot read your content unless it ships
you malicious client code. T3 remains, accepted (D1), and is what the native
client removes. C4 is reduced, not closed, until 13.3. Chat is still plaintext at
rest until Phase 15. Draft-v5 §2 states each claim against the adversary it holds
against, which is the convention this branch exists to keep.
Four defects were found by deploying it and using a browser, none by the test
suite: a node going deaf on its hub socket, a token that predated group
membership, a client reading values before they were assigned, and identity keys
a browser held but never re-read. The lessons are recorded in CLAUDE.md.
Tests: 343 across the three packages, plus QE/deploy/e2e.py — register, pair,
invite, join, download, stream, second browser, revoke — run against the live
deployment on a wiped hub and node.
Diffstat (limited to 'tmp-decisions.md')
| -rw-r--r-- | tmp-decisions.md | 48 |
1 files changed, 33 insertions, 15 deletions
diff --git a/tmp-decisions.md b/tmp-decisions.md index 97a27ea..347d771 100644 --- a/tmp-decisions.md +++ b/tmp-decisions.md @@ -1,7 +1,8 @@ -# Open decisions — client architecture +# Client architecture — decisions -> Working note, not a spec. Created 2026-08-13 after the second security review. -> Delete or fold into `docs/meshbay-draft-v5.md` once decided. +> Created 2026-08-13 after the second security review. D1/D2/D3 decided the same day; +> D4 (hub minimization) deferred. Fold into `docs/meshbay-draft-v5.md`. +> The analysis below is kept as the rationale behind the decisions, not as open questions. --- @@ -9,18 +10,35 @@ | # | Decision | State | |---|---|---| -| D1 | Does the hub keep serving the web UI? | **Open** — leaning yes | -| D2 | Browser extension, native desktop client, or both? | **Open** — needs time | +| D1 | Does the hub keep serving the web UI? | ✅ **DECIDED 2026-08-13 — yes** | +| D2 | Browser extension, native desktop client, or both? | ✅ **DECIDED 2026-08-13 — native client, offered alongside the hub-served SPA** | | D3 | Transport: aiortc primary, QUIC at parity, TCP+HTTP removed | ✅ Decided 2026-08-13 | +| D4 | Hub minimization (old Phase 12) | ⏸️ **Deferred, may be dropped** | -**Neither D1 nor D2 blocks anything right now.** Phase 11.5 (security remediation), -Phase 12 (hub minimization), Phase 14 (node CLI) and Phase 15 (Sender Keys) are entirely -client-agnostic — every finding they close is node-side or hub-side. Phase 11.5 is in -progress on that basis. +**What was decided.** The hub keeps serving the web UI — that is the zero-install path +and it stays. A native desktop client is offered *in addition*, not as a replacement. +Hub minimization is off the critical path and may be dropped entirely. ---- +**What that means, stated once and then respected.** Keeping the hub in the trusted path +is a legitimate product call, and this project is not obliged to defend against its own +operator. But two consequences should be carried deliberately rather than by accident: + +1. **T3 is accepted permanently for browser users.** A hub that serves the code can + exfiltrate keys from the page regardless of what the protocol does. The native client + gives users who care an alternative; browser users are trusting meshbay.org, and the + docs should say so plainly rather than claiming end-to-end integrity. +2. **H3 was the last open High finding and its only fix lived in the dropped phase.** + The hub is the public key directory: substituting a key during an invite hands it the + group key, silently, with no forgery and no code injection. So key transparency and + safety numbers were kept and are now Phase 12.1 — everything else from hub + minimization is dropped. If Phase 12 is later dropped too, H3 stays open by choice, + and "unreadable by other parties, even the hub" stops being a claim the project can + make about an adversarial hub. + +The honest framing that survives all of this: **the hub cannot read your content unless +it actively attacks you.** That is still a strong property, and it is defensible. -## Why these are open +## Rationale — why the native client is not a T3 fix The second review recommended a native client and claimed *"T3 disappears — code integrity stops depending on the hub."* **That claim was wrong and has been corrected** in @@ -52,12 +70,12 @@ It should not be justified as the fix for T3 unless 18.7 ships with it. --- -## D1 — Should the hub keep serving the UI? +## D1 rationale — hub keeps serving the UI ✅ Keeping it is defensible. It is how anyone tries the platform without installing anything, and it stays the fallback when a device has no client installed. -What must be true if it stays (all already scheduled in Phase 12.6): +What must be true now that it stays (Phase 12.2/12.3): - strict CSP and Subresource Integrity on the bundle - the hub publishes a **signed digest** of the served bundle, so any third party — an @@ -69,7 +87,7 @@ The honest framing: hub-served SPA is a **convenience tier**, not the secure tie --- -## D2 — Extension vs native: what each actually covers +## D2 rationale — native chosen; extension not taken up Three shapes, cheapest first: @@ -85,7 +103,7 @@ hub operator does not control**. Manifest V3 forbids remote code, which works in the structure enforces exactly what we want. Keys live in extension storage, isolated from page JS. Moderate effort. -**Option C — Native desktop client (pywebview + aiortc)** +**Option C — Native desktop client (pywebview + aiortc)** ← **CHOSEN** Phase 13. Full control, durable keys in an OS keystore, QUIC, hub-less access, best UX. Highest effort, and the security argument depends on 18.7. |