Skip to content

[P1] Design authenticated pairing and encrypted transfers #4

Description

@Gaalbu

Problem

Protocol v1 relies on user approval and opaque session IDs but sends file content over unencrypted HTTP and does not authenticate peer identity.

Acceptance criteria

  • Threat-model an attacker on the same LAN.
  • Select reviewed libraries/protocols for pairing, authentication and encryption.
  • Define key verification and rotation UX for Android and Linux.
  • Preserve explicit approval and avoid custom cryptographic primitives.
  • Add interoperability and downgrade tests before changing protocolVersion.

Metadata

Metadata

Assignees

No one assigned

    Labels

    architecturePortfolio hardening: architecturesecurityPortfolio hardening: security

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions