3 ms·
Maker here. I’m especially interested in criticism of the threat model. If you try it, I’d love feedback on: which rule is actually useful in practice (time/g
by dkatsura 7mo ago
Maker here. I’m especially interested in criticism of the threat model.
If you try it, I’d love feedback on:
which rule is actually useful in practice (time/geo/visual key)
what is confusing in setup
what would increase trust fastest (spec, vectors, reproducible builds)
- dkatsura 7mo agoIf useful, I can post a minimal capsule format sketch (header + policy fields) and a compact threat-model table (what it protects vs. what it does not).
- dkatsura 7mo agoAs promised, here’s a minimal sketch. *Capsule format (high-level)* * magic + version * crypto suite id (AEAD) * KDF id + parameters (for password path) * salt / nonces * policy section (time/geo/password/visual, AND/OR AST) * ciphertext (payload blob) * auth tag / integrity *Threat model (compact)* Protects against: * someone who only gets the `.cfcaps` file (without required secrets/rules) * accidental/premature access during sharing (time/place/team constraints) Does not protect against: * fully compromised endpoint/runtime (bypass checks / exfiltrate plaintext after legitimate open) * malicious recipient taking photos/screenshots once content is opened If people want, I can write a 1-page spec from this (policy AST fields + encoding).
- dkatsura 7mo agoDesign question: for Windows geo I chose a phone relay (QR challenge/proof) instead of trusting desktop location APIs. Is that the right tradeoff in your view, or would you prefer a different approach?