Egregoros

Signal feed

Timeline

Post

Remote status

Replies

7
@dch @feld @ClickyMcTicker @cR0w The idea behind it after reading through some of the draft is that it prevents unauthorized changes to the network.

When I join your network while not being authorized to do so, I should not be able to access anything on the network. Or at least that's how I understood it, since the draft is ambiguous about it and doesn't really explain it. So I guess things like ARP spoofing on a local network should then be impossible, because the responses aren't authorized by a valid JWT token.