NEC-98: Say precisely what the hosted service holds that the passphrase bears on #197
No reviewers
Labels
No labels
area:docs
area:identity
area:ops
area:plugin
area:server
channel:community
channel:direct
channel:owned
channel:press
channel:social
e2ee-constrained
gate:at-ga
gate:pre-ga
marketing
parity
relay:absent
relay:planned
relay:requested
relay:supported
risk:additive
risk:contract
risk:none
usability
No milestone
No project
No assignees
2 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
Nectenda/nectenda!197
Loading…
Reference in a new issue
No description provided.
Delete branch "worktree-nec-98-say-precisely-what-the-hosted-service-hol"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Task: NEC-98 — https://projectron.nerchure.com/tasks/98
Several copies of the security claim said the hosted service receives "nothing derived from the passphrase". That is false: it stores the private key wrapped under a passphrase-derived key. This narrows the privacy notice, terms, key-storage.md, the purchase email, the plugin's published comments and both READMEs to what is true, that no hash or verifier is sent, and pins the wording in security-model-claims.test.ts. Review found that security-model.md and CRYPTO-025 still overclaimed. They called the wrapped key the only passphrase-bound value held, but user_key_history keeps every earlier wrapping, and they said the master key is never stored, but the recovery blob is that key sealed. Both are now disclosed and pinned (NEC-140). Documentation and comments only; no code path changes.
Spec:
docs/changes/NEC-98-passphrase-derived-claims/spec.mdAlso fixes NEC-140: Security model says the wrapped private key is the only passphrase-bound value held
Also fixes NEC-141: README says keys are derived from the password and never reach the server
Changelog
The privacy notice, terms, security model and purchase email now say exactly what the hosted service holds that your passphrase bears on: never a hash or verifier of it, but your private key wrapped under it, including earlier wrappings kept after a passphrase change.
1c321dbc408fecd219da