Skip to main content

Decision

Privacy is treated as an accountability-first design: probes are public, on-chain settlement is what makes payment auditable, and the registry is what makes nodes discoverable and slashable. Most privacy surfaces are accepted as inherent. Two are mitigated; deeper techniques are assessed and not adopted.

Adversary model (four tiers)

Each tier subsumes the one above it.

Privacy surfaces

The protocol inventories its distinct privacy surfaces with explicit dispositions (accept or mitigate). Highlights:
  • On-chain settlement volume leakage. Anyone can read pool deposits and per-node redemptions on-chain. Accepted: auditable settlement is what makes the payment layer trustless.
  • Signed protocol messages as a content inventory. A signed availability response is non-repudiable proof that the node held (or did not hold) a specific hash at a specific time, and accumulated signatures build a verifiable inventory. Accepted: the same signature is what enables on-chain accountability.
  • Probe traffic. Who probes what is visible to every candidate probed, not just the one selected. Accepted: the delivering node must learn the hash regardless, so hiding the request from the others adds bandwidth without changing the underlying property.
  • Registry enumeration. Anyone can read the active set and each node’s self-reported region and addresses. Accepted: an enumerable, slashable operator set is the point.

Mitigations

  1. Client key storage. The design keeps client keys in OS-level secure storage — the macOS Keychain, Windows Credential Manager, or the Linux Secret Service — rather than plaintext files on disk.
  2. Operational RPC guidance. Clients and nodes query through multiple independent RPC providers, or a self-hosted node, so no single vendor sees the whole query pattern.

Assessed and not adopted

  • Client identity rotation. Rotating the transport identity between sessions is a supported capability, but it is not a privacy commitment: every request carries the pool identifier, and a serving node must resolve the signer’s address to be paid at all. That stable payment identity is what an observer correlates on, regardless of node count — so rotation obscures only non-serving probers, whose view is already accepted above.
  • Dummy probes. Cover-traffic probes hide requests only from nodes that were never going to deliver — the delivering node must learn the hash regardless — 3–5× the probe traffic for marginal benefit.
  • Payment pool mixing. Breaking the on-chain payer↔provider link needs regulatory analysis before any design work. Pools are also long-lived and amortized across many sessions, so they reveal less than per-transfer settlement would.

Scope clarifications

  • Content plaintext is a content-provider concern, and application-level privacy is out of scope. If sensitivity requires it, the content provider encrypts before publishing.
  • Client IP addresses are visible to peers, and to a relay host on any relayed connection. Network-level anonymity is not a protocol goal.