aboutsummaryrefslogtreecommitdiffstats
path: root/docs/playlists.md
diff options
context:
space:
mode:
Diffstat (limited to 'docs/playlists.md')
-rw-r--r--docs/playlists.md7
1 files changed, 7 insertions, 0 deletions
diff --git a/docs/playlists.md b/docs/playlists.md
index c41c71f..f1f6b67 100644
--- a/docs/playlists.md
+++ b/docs/playlists.md
@@ -220,6 +220,13 @@ bundles. So:
playlist_key = HKDF-SHA256(bundle_key_v2, info = "meshbay:playlists:v1")
```
+> **Superseded (0.17.0).** A key from the passphrase alone made every sealed
+> blob an offline oracle for it on every node. The key is now
+> `HKDF-SHA256(M, info = "meshbay:playlists:v2")`, where `M` folds in a pepper
+> the hub holds, and a blob that does not open under it is overwritten with the
+> local copy — `MESHBAY_DESIGN.md` §3.7 and §9.10. The rest of this section is
+> the reasoning as it stood, and still holds for `M`.
+
Three consequences, each of which is a line of code somewhere:
- **`deriveEncryptionKey` must return an HKDF handle as well as the AES-GCM