Extends the Block 2 spike to attack the highest-risk unbuilt piece (private messaging) and to prove the Q2 architecture recommendation with running code: - NostrConnection: one shared socket+key+sign+REQ/EOSE lifecycle. Refactored NostrOfferTransport onto it; added NostrMessageTransport — two thin contracts on ONE connection (the 'one connection, three interfaces' shape). - NIP-44 v2 encryption (secp256k1 ECDH -> ChaCha20 + HMAC, length-hiding pad). - NIP-17/NIP-59 gift-wrap: rumor(14) -> seal(13) -> wrap(1059, ephemeral key). Alice->Bob DM round-trips through the relay: encrypted, sender authenticated, and metadata-private (relay/eavesdropper sees only ciphertext, an ephemeral author and the recipient p-tag — Alice stays hidden). Findings updated: NIP-17 risk drops Medium-High -> Medium (hardening, not feasibility); next de-risking target is the web of trust. NIP-44 not yet vector-verified (noted). 20 tests green, analyzer clean, Block 1 untouched. |
||
|---|---|---|
| .. | ||
| backup-and-recovery.md | ||
| block1-status.md | ||
| core-domain-boundary.md | ||
| data-model.md | ||
| data-notes.md | ||
| first-sprint.md | ||
| g1-integration.md | ||
| network-trust.md | ||
| open-decisions.md | ||
| security-privacy.md | ||
| sharing-model.md | ||
| spike-block2-findings.md | ||
| testing.md | ||
| usability-and-architecture.md | ||