Seq 09/17 · Priority P1 · Blocked by: #295,#296 · Tracked in #312
Ensure the initial server upload is a sealed AEAD snapshot so only sealed ciphertext ever leaves the device.
Do
- Define + implement a sealed AEAD initial-snapshot format (ciphertext only; no key material in headers).
- Upload existing vault contents as first server state via that sealed format; prohibit uploading the raw local working store.
- Cross-client seal/unseal test vectors.
Components: core/cli/ios/web · Size: L.
Ensure the initial server upload is a sealed AEAD snapshot so only sealed ciphertext ever leaves the device.
Do
Components: core/cli/ios/web · Size: L.