From 0d9d91eeea9001ea3838272416e3d526b6a2a1fc Mon Sep 17 00:00:00 2001 From: Christophe Besson Date: Thu, 1 Oct 2026 12:05:12 +0200 Subject: docs: chat at rest is protected from a copy without the unlock key, not from a disk MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit unlock.key sits beside keystore.enc by default, so a whole disk, an image or a home-directory backup opens the stored chat. The claims table, §4.5 and the user guide say so and name what protects those: disk encryption, or the unlock key on other storage (F-20). Co-Authored-By: Claude Opus 5.5 --- docs/USERGUIDE.md | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) (limited to 'docs/USERGUIDE.md') diff --git a/docs/USERGUIDE.md b/docs/USERGUIDE.md index eb9452e..e92f6bc 100644 --- a/docs/USERGUIDE.md +++ b/docs/USERGUIDE.md @@ -893,13 +893,22 @@ the confirmation on destructive commands. `man meshbay-node` has the full page. | `~/.config/meshbay/node.toml` | configuration — hand-edited, commented, preserved | | `~/.config/meshbay/node.env` | environment: keystore unlock, third-party tokens | | `~/.config/meshbay/keystore.enc` | the node's own keys. **Back this up.** | -| `~/.config/meshbay/unlock.key` | what opens the keystore. Mode 0600. | +| `~/.config/meshbay/unlock.key` | what opens the keystore. Mode 0600. Whoever has both files opens the keystore, and with it the group chat this node stores | | `~/.local/share/meshbay/` | roster, indexes, chat, caches, thumbnails | | `/opt/meshbay-common/venv/` | the shared Python environment | Losing the keystore means a new node identity: every group has to be re-linked and every member re-admitted. It is small — back it up somewhere safe. +The chat this node stores is encrypted under the keystore, and the keystore is +opened by `unlock.key`, which sits beside it. A stolen disk, an image of the +machine or a backup of your home directory therefore holds everything needed to +read it. What protects those is the disk's own encryption — BitLocker or device +encryption on Windows, LUKS on Linux — or keeping the unlock key on other +storage: point `[keystore] unlock_file` in `node.toml` at it and remove +`unlock.key`. (`node.env` is in the same directory, so moving the key there +changes nothing.) The node then cannot start without that storage. + ### Ports | | | -- cgit v1.2.3