Skip to content

MB/B1: Sealed AEAD initial snapshot + encrypted first-account upload #303

Description

@kafkade

Seq 09/17 · Priority P1 · Blocked by: #295,#296 · Tracked in #312

Ensure the initial server upload is a sealed AEAD snapshot so only sealed ciphertext ever leaves the device.

Do

  • Define + implement a sealed AEAD initial-snapshot format (ciphertext only; no key material in headers).
  • Upload existing vault contents as first server state via that sealed format; prohibit uploading the raw local working store.
  • Cross-client seal/unseal test vectors.

Components: core/cli/ios/web · Size: L.

Metadata

Metadata

Assignees

No one assigned

    Labels

    area/cryptoEncryption, key management, vaultarea/syncCross-device sync, conflict resolutionpriority/P1-highRequired for a credible v1.3 / core promisesecuritySecurity-related issuetype/featureNew feature

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions