checkpoint: docs honesty fix at d4d87b8 (2026-09-22)
This commit is contained in:
parent
d4d87b85b6
commit
2e5938a3fa
1 changed files with 54 additions and 0 deletions
|
|
@ -1,3 +1,57 @@
|
||||||
|
# Checkpoint — 'keys never leave' claim corrected per-mode (2026-09-22); prior: pairing forensics de-noised
|
||||||
|
|
||||||
|
## Where things are
|
||||||
|
- Project: `/home/avi/Projects/Keynctr`
|
||||||
|
- Branch: `master` @ **`d4d87b8`** ("docs: replace blanket 'keys never leave
|
||||||
|
the machine' claim with per-mode truth"). Previous: `f6bf6a9`, `edd4e56`
|
||||||
|
(pairing feature HEAD), `deeb4f9`, `d52fa58`.
|
||||||
|
- Working tree: clean for tracked files. Untracked intentionally NOT
|
||||||
|
committed: `COSMIC_THEME.md`, `KeynectrAppIconPossibility02.jpeg`,
|
||||||
|
`deferred/` (stays deferred).
|
||||||
|
- Release binary: still built at `f6bf6a9` — `d4d87b8` changed only
|
||||||
|
Markdown docs, no rebuild needed.
|
||||||
|
- Verification at `d4d87b8`: `cargo fmt --check` clean, `cargo test` **208
|
||||||
|
unit + 3 e2e passed / 0 failed** (first run showed 1 e2e flake; both the
|
||||||
|
targeted `cargo test --test nip46_e2e` rerun and the full rerun were
|
||||||
|
green). No frontend changes (npm suite last green at `edd4e56`).
|
||||||
|
|
||||||
|
## What was completed since the last checkpoint
|
||||||
|
- **Honest security copy (`d4d87b8`)**: the blanket "keys never leave the
|
||||||
|
machine" claim in README.md (tagline), PRODUCT.md (purpose, positioning,
|
||||||
|
principle 1), and DESIGN.md (North Star) was replaced with the per-mode
|
||||||
|
truth: in embedded/bunker modes keys stay in the local encrypted vault
|
||||||
|
and never reach the renderer; in external NIP-46 signer mode the key
|
||||||
|
never *arrives* on this machine — a strictly stronger posture against
|
||||||
|
desktop compromise. README security notes gained an explicit bullet
|
||||||
|
saying external signer mode can be *more* secure. App UI
|
||||||
|
(`SignerModeScreen.tsx`) already ranked external signer "Most Secure /
|
||||||
|
Private key NEVER on this device" — no code or test changes were needed.
|
||||||
|
|
||||||
|
## Commits added (newest first)
|
||||||
|
- `d4d87b8` docs: replace blanket 'keys never leave the machine' claim with per-mode truth
|
||||||
|
|
||||||
|
## How to reproduce / exercise
|
||||||
|
- **LIVE AMBER TEST (still the only missing step from `f6bf6a9`)**: launch
|
||||||
|
the app: `cd frontend && npx vite --port 5173` then
|
||||||
|
`NOSTR_GUI_DEV_URL=http://localhost:5173 KEYNCTR_ENABLE_GPU=1 npx electron .`
|
||||||
|
Signer mode -> Show QR -> scan in Amber -> approve. Expected trace:
|
||||||
|
`pairing started: ephemeral=…` -> `inbound 24133 from …` -> `connect
|
||||||
|
response accepted (secret echo verified)` -> `paired: connection stored;
|
||||||
|
handing over to identity handshake` -> `identity adopted: npub=… —
|
||||||
|
CONNECTED`. Watch with `bash ~/Tools/keynctr-debug/watch-pairing.sh 240`.
|
||||||
|
- Docs-only change: `git show d4d87b8`.
|
||||||
|
|
||||||
|
## Outstanding / next steps
|
||||||
|
1. **Live Amber re-scan required** (cannot be done from an unattended run).
|
||||||
|
2. If trace shows `pre-handshake 'get_public_key' ignored`, relax the
|
||||||
|
connect-only gate.
|
||||||
|
3. `publish_profile_metadata` (kind 0) still signs locally — reroute
|
||||||
|
through `Signing` for external profiles (P2).
|
||||||
|
4. Step 5 (KDF upgrade), Step 6 (undo preserves ProfileSummary), Step 7
|
||||||
|
(rename pass incl. `homepage` URL).
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
# Checkpoint — pairing forensics fully de-noised; Amber fix still awaiting live test (2026-09-21)
|
# Checkpoint — pairing forensics fully de-noised; Amber fix still awaiting live test (2026-09-21)
|
||||||
|
|
||||||
## Where things are
|
## Where things are
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue