Write the security explainer #98
Labels
No labels
area:docs
area:identity
area:ops
area:plugin
area:server
channel:community
channel:direct
channel:owned
channel:press
channel:social
e2ee-constrained
gate:at-ga
gate:pre-ga
marketing
parity
relay:absent
relay:planned
relay:requested
relay:supported
risk:additive
risk:contract
risk:none
usability
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
Nectenda/nectenda#98
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Why
This is the artefact that earns the right to post in r/netsec, gets submitted to
security newsletters, and gives a writer something to verify rather than repeat.
It is also the strongest form of the product's second pillar: the claim is
checkable, so show the check.
What to do
A technical write-up of the security model, pitched at someone who could
implement it. The content already exists in
docs/security-model.md; this turnsit into something a reader arrives at cold.
Ground to cover:
HMAC-SHA256(nameKey, path)truncated to 16 bytes — sopaths, folder structure and note titles never reach us.
binds blob id, chunk index, chunk count and algorithm.
server can read.
the hosted service nothing derived from it is sent at all.
wrapped per member with ECIES over P-256, fresh ephemeral keypair per wrap.
Signal safety numbers.
the SHA-256 of the bundle, and
scripts/verify-build.mjsreproduces it frompublished source. Verified byte-identical from a clean clone on 18 September
2026.
Constraints
security audience that finds an unstated limit stops reading everything else.
implies more than we do. Never "we store no metadata" — the membership graph,
account and device records, sizes, timings and IPs are all stored.
that someone will check.
Moved to the Vikunja board as NEC-74: https://projectron.nerchure.com/tasks/74