From 2e5938a3fa8ab14b2df8790c75990db45a5737ba Mon Sep 17 00:00:00 2001 From: Avi Date: Tue, 22 Sep 2026 17:47:06 -0500 Subject: [PATCH] checkpoint: docs honesty fix at d4d87b8 (2026-09-22) --- CHECKPOINT-encryption.md | 54 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 54 insertions(+) diff --git a/CHECKPOINT-encryption.md b/CHECKPOINT-encryption.md index a28541a..1c7d768 100644 --- a/CHECKPOINT-encryption.md +++ b/CHECKPOINT-encryption.md @@ -1,3 +1,57 @@ +# Checkpoint — 'keys never leave' claim corrected per-mode (2026-09-22); prior: pairing forensics de-noised + +## Where things are +- Project: `/home/avi/Projects/Keynctr` +- Branch: `master` @ **`d4d87b8`** ("docs: replace blanket 'keys never leave + the machine' claim with per-mode truth"). Previous: `f6bf6a9`, `edd4e56` + (pairing feature HEAD), `deeb4f9`, `d52fa58`. +- Working tree: clean for tracked files. Untracked intentionally NOT + committed: `COSMIC_THEME.md`, `KeynectrAppIconPossibility02.jpeg`, + `deferred/` (stays deferred). +- Release binary: still built at `f6bf6a9` — `d4d87b8` changed only + Markdown docs, no rebuild needed. +- Verification at `d4d87b8`: `cargo fmt --check` clean, `cargo test` **208 + unit + 3 e2e passed / 0 failed** (first run showed 1 e2e flake; both the + targeted `cargo test --test nip46_e2e` rerun and the full rerun were + green). No frontend changes (npm suite last green at `edd4e56`). + +## What was completed since the last checkpoint +- **Honest security copy (`d4d87b8`)**: the blanket "keys never leave the + machine" claim in README.md (tagline), PRODUCT.md (purpose, positioning, + principle 1), and DESIGN.md (North Star) was replaced with the per-mode + truth: in embedded/bunker modes keys stay in the local encrypted vault + and never reach the renderer; in external NIP-46 signer mode the key + never *arrives* on this machine — a strictly stronger posture against + desktop compromise. README security notes gained an explicit bullet + saying external signer mode can be *more* secure. App UI + (`SignerModeScreen.tsx`) already ranked external signer "Most Secure / + Private key NEVER on this device" — no code or test changes were needed. + +## Commits added (newest first) +- `d4d87b8` docs: replace blanket 'keys never leave the machine' claim with per-mode truth + +## How to reproduce / exercise +- **LIVE AMBER TEST (still the only missing step from `f6bf6a9`)**: launch + the app: `cd frontend && npx vite --port 5173` then + `NOSTR_GUI_DEV_URL=http://localhost:5173 KEYNCTR_ENABLE_GPU=1 npx electron .` + Signer mode -> Show QR -> scan in Amber -> approve. Expected trace: + `pairing started: ephemeral=…` -> `inbound 24133 from …` -> `connect + response accepted (secret echo verified)` -> `paired: connection stored; + handing over to identity handshake` -> `identity adopted: npub=… — + CONNECTED`. Watch with `bash ~/Tools/keynctr-debug/watch-pairing.sh 240`. +- Docs-only change: `git show d4d87b8`. + +## Outstanding / next steps +1. **Live Amber re-scan required** (cannot be done from an unattended run). +2. If trace shows `pre-handshake 'get_public_key' ignored`, relax the + connect-only gate. +3. `publish_profile_metadata` (kind 0) still signs locally — reroute + through `Signing` for external profiles (P2). +4. Step 5 (KDF upgrade), Step 6 (undo preserves ProfileSummary), Step 7 + (rename pass incl. `homepage` URL). + +--- + # Checkpoint — pairing forensics fully de-noised; Amber fix still awaiting live test (2026-09-21) ## Where things are