Skip to content

[RFC] Define the RelayOS threat model and protocol v1 #1

Description

@rufatixx

Outcome

Write a reviewable threat model and a versioned protocol-v1 specification before adding a physical transport.

Scope

  • assets, attackers, trust boundaries, and metadata exposure
  • recipient-key discovery and verification assumptions
  • authenticated and unauthenticated packet fields
  • replay, clock-skew, denial-of-service, and compromised-recipient cases
  • compatibility rules for packet format changes
  • explicit non-goals for the alpha

Acceptance criteria

  • A document is added under docs/.
  • Every current cryptographic claim in the README maps to the document.
  • Open questions and decisions are clearly separated.
  • The proposal is reviewed before implementation changes begin.

This issue is design work. It must not claim that RelayOS has been audited.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: protocolPacket format, compatibility, and protocol designenhancementNew feature or requesthelp wantedExtra attention is neededstatus: needs designRequires an agreed design before implementation

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions