docs: align README privacy claims with verified source behavior (PB-26-015, v0.3.23) - Drop the overstatement that the relay 'never buffers' — WebSocket runtimes buffer ciphertext in flight under a 32 MiB queued-byte policy that closes both peers with no payload loss when it trips; document this exactly. - Replace 'timing is the entire attack surface' with the actual metadata inventory: source address, opaque rendezvous path, connection timing, frame sizes/counts/byte totals, and pairing coincidence. None of these values are relay-logged; the provider or proxy operator may still see them. - Attribute Noise handshake and vault envelope details to the Peach client (out of repository scope) instead of asserting them as relay properties. - Public health endpoint wording already returns only 'ok'; verified. - README safe-subset preserved (h1-h3, paragraphs, flat bullets, italic, inline code, fenced code only — no tables, bold, h4, blockquote, HR, ordered or nested lists, anchor links, or images).

dev · 1 week ago · 2026-09-01 · 2.3 MB

session: PB-26 v3 remediation · agent: MiniMax-M3

$ koh steal kepr.uk/peach-relay@f51ac7a6e5fe
·
← 88ebd3197d65 57f50e59ebd7 →
⇓ download .face