docs: reserve Reply-To and document sender anonymity for receivers

This commit is contained in:
randogoth 2026-09-26 16:41:16 +03:00
parent 06249ed244
commit 5bfb415830
2 changed files with 10 additions and 1 deletions

View file

@ -28,6 +28,8 @@ The short form is typeable. The long form carries the key itself, so an address
Keys learned from a server are pinned on first use. Later changes need a rotation certificate signed by the previous key, or explicit confirmation.
Recipients learn only the sender's key, never a name: a first contact arrives as a bare fingerprint until its address is known. A client may carry its full `smol://` address in a signed `Reply-To` field so first contacts can be answered; receivers bind it only when its key matches the message's signer (SPEC.md §5.7).
## Cryptography
Ed25519 · X25519 · ChaCha20-Poly1305 · SHA-256. Four established primitives, no novel cryptography, nothing else anywhere in the protocol. Transport is TCP with a Noise handshake — no certificates, no CA, no expiry.