diff --git a/WS.md b/WS.md index 825fe79..504e85d 100644 --- a/WS.md +++ b/WS.md @@ -62,9 +62,9 @@ Most servers are TCP only, so a browser client reaches most hosts through a rela A relay sees ciphertext only when the host is pinned, and a relay that tampers then produces a failed handshake or a pin mismatch. Against an unpinned host a relay can complete the handshake itself and present its own key, with no failure to notice: the first-contact interception ยง4 already describes, whose rules are the defence -- the session is unverified, MUST be shown as such, and MUST NOT carry `REGISTER`, `FETCH` or `DELETE`. A relay does learn the client's IP address and every host the client contacts, and the server learns the relay's address in place of the client's, so a client SHOULD use only a relay run by a party it would trust with that list; for a browser client that is the origin serving its code, which it already trusts with the master. Bounding a relay as a proxy is its operator's hardening and outside this annex. - ## Status +## Status - Only the byte format is implemented, by the [gsmol](https://code.randogoth.com/randogoth/gsmol) bridge acting as a relay. The endpoint, the subprotocol name and the sidecar are not implemented anywhere yet. +Only the byte format is implemented, by the [gsmol](https://code.randogoth.com/randogoth/gsmol) bridge acting as a relay. The endpoint, the subprotocol name and the sidecar are not implemented anywhere yet. ## License