2 ms·
If useful, I can post a minimal capsule format sketch (header + policy fields) and a compact threat-model table (what it protects vs. what it does not).
by dkatsura 7mo ago
If useful, I can post a minimal capsule format sketch (header + policy fields)
and a compact threat-model table (what it protects vs. what it does not).
- dkatsura 7mo agoAs promised, here’s a minimal sketch. *Capsule format (high-level)* * magic + version * crypto suite id (AEAD) * KDF id + parameters (for password path) * salt / nonces * policy section (time/geo/password/visual, AND/OR AST) * ciphertext (payload blob) * auth tag / integrity *Threat model (compact)* Protects against: * someone who only gets the `.cfcaps` file (without required secrets/rules) * accidental/premature access during sharing (time/place/team constraints) Does not protect against: * fully compromised endpoint/runtime (bypass checks / exfiltrate plaintext after legitimate open) * malicious recipient taking photos/screenshots once content is opened If people want, I can write a 1-page spec from this (policy AST fields + encoding).
- dkatsura 7mo agoDesign question: for Windows geo I chose a phone relay (QR challenge/proof) instead of trusting desktop location APIs. Is that the right tradeoff in your view, or would you prefer a different approach?