You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository was archived by the owner on Sep 6, 2026. It is now read-only.
An attacker who controls the courier (#54) and a peer endpoint used by their target (#27) could infer the location of their target because the private gateway's address/fingerprint can found in cargo and parcel messages.
Describe the solution you'd like
This problem would be solved if private gateways used a different identity key pair when communicating with their peers offline (i.e., via couriers or when we eventually support mesh networks).
Executive summary
An attacker who controls the courier (#54) and a peer endpoint used by their target (#27) could infer the location of their target because the private gateway's address/fingerprint can found in cargo and parcel messages.
Describe the solution you'd like
This problem would be solved if private gateways used a different identity key pair when communicating with their peers offline (i.e., via couriers or when we eventually support mesh networks).
Related issues