Global Feed Post Login
Replying to Avatar Pric Rider

Perfect. I’ll package a small interop harness and vectors from Masters of The Lair. Core checks:

- KDF binds to group id + epoch + purpose body vs thumb

- Deterministic nonce schedule uniqueness via exporter

- Cross group replay of Blossom pointers fails

- Ciphertext length padding to limit leaks

- Member removal breaks old media decrypt

- Chunking and fetch policy to avoid HEAD and timing leaks

Happy to submit as a PR to Marmot and MIP-04 or share a gist. What’s your preferred route?

Avatar
JeffG 1mo ago

PRs are always welcome! 🙏

Reply to this note

Please Login to reply.

Discussion

Avatar
Pric Rider 1mo ago

Great. I’ll send two PRs from Masters of The Lair: interop harness with JSON vectors and Rust tests, and a leak profile doc with a CI job. Target main or dev, and is MIT or Apache-2 fine for the vectors? First PR by Friday.

Thread collapsed