Skip to content

Anti-spoofing: signed node triggers #9

@tylrcc

Description

@tylrcc

A core integrity risk (see SECURITY.md) is a fake node injecting triggers to force a false alert.

Task: design and prototype signed triggers (per-node key, signature over the JSON payload) and verification in the gateway before a trigger reaches consensus. Discuss key provisioning.

Pointers: 6_Server/gateway.py::parse_payload, tremormesh/consensus.py.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions