summaryrefslogtreecommitdiffstats
path: root/docs
diff options
context:
space:
mode:
Diffstat (limited to 'docs')
-rw-r--r--docs/USERGUIDE.md13
1 files changed, 12 insertions, 1 deletions
diff --git a/docs/USERGUIDE.md b/docs/USERGUIDE.md
index af03a60..ccbf112 100644
--- a/docs/USERGUIDE.md
+++ b/docs/USERGUIDE.md
@@ -533,7 +533,7 @@ player.load();
- Fetching the M3U8 playlist
- Requesting encrypted chunks on demand
- Deriving per-chunk keys from the GEK
-- Decrypting with WebCrypto (ChaCha20-Poly1305)
+- Decrypting with WebCrypto (AES-256-GCM — see §8 for cipher choice)
- Feeding plaintext segments to MSE
### Seeking
@@ -550,6 +550,17 @@ The node can serve HLS for any container it can segment at 1 MB boundaries: MP4,
Understanding what the hub knows — and does not know — is essential for evaluating MeshBay's threat model.
+### Cipher choices — symmetric, not asymmetric
+
+Clarification terminology : Ed25519 et X25519 sont des algorithmes **asymétriques** (paire clé publique/privée). Ils servent à la signature et à l'échange de clés. Les ciphers de chiffrement de contenu sont eux **symétriques** (une seule clé partagée, la GEK) :
+
+| Cipher | Usage | Où |
+|---|---|---|
+| **ChaCha20-Poly1305** | Chiffrement contenu (MNP) | Node → client natif (Python, Android) |
+| **AES-256-GCM** | Chiffrement contenu (navigateur) | Variante pour les groupes accessibles depuis un browser (WebCrypto ne supporte pas ChaCha20) |
+
+Les deux sont des AEAD 256 bits avec authentification intégrée. ChaCha20 est le cipher **principal** — AES-GCM est une variante optionnelle pour la compat navigateur, pas un remplacement. Un groupe ne peut pas mélanger les deux : un groupe "browser-accessible" utilise AES-GCM pour tous ses membres.
+
### What the hub stores
| Data | Stored as |