Commit a510b2f
committed
docs: describe the security boundary and how to harden a plugin
The SDK ships no anti-tamper, anti-debug, obfuscation or integrity-checking
code, and that is a deliberate scope decision rather than an oversight. Nothing
in the documentation said so, so a reader could reasonably finish the README
believing it was a DRM layer, wire `licensedFlag()` into a single `processBlock`
branch, and ship.
A new "Security and hardening" section sits between the device fingerprint and
3.x migration sections, keeping the trust material together: how the binding is
computed, then what it does and does not buy you. It states what the SDK
guarantees (only Moonbase can mint a token, the product and device bindings, the
bounded grace period, the store being a cache rather than a credential,
fail-closed defaults), why hardening is deliberately left to the consumer, and
seven principles for doing it.
The rationale for the boundary is the part worth keeping: hardening only works
when it lives inside your binary and is specific to it, so anything general
enough to ship in an open-source header would be public, identical in every
plugin using it, and one published bypass would apply to all of them.
Guidance is positive throughout. The section does not enumerate the SDK's weak
points or publish attack recipes. Much of the reasoning already existed in code
comments that consumers never read, notably the on-disk cache warning in
device_id_resolver.hpp and the fail-closed default in LicenseGate.h.1 parent 960ba54 commit a510b2f
1 file changed
Lines changed: 59 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
323 | 323 | | |
324 | 324 | | |
325 | 325 | | |
| 326 | + | |
| 327 | + | |
| 328 | + | |
| 329 | + | |
| 330 | + | |
| 331 | + | |
| 332 | + | |
| 333 | + | |
| 334 | + | |
| 335 | + | |
| 336 | + | |
| 337 | + | |
| 338 | + | |
| 339 | + | |
| 340 | + | |
| 341 | + | |
| 342 | + | |
| 343 | + | |
| 344 | + | |
| 345 | + | |
| 346 | + | |
| 347 | + | |
| 348 | + | |
| 349 | + | |
| 350 | + | |
| 351 | + | |
| 352 | + | |
| 353 | + | |
| 354 | + | |
| 355 | + | |
| 356 | + | |
| 357 | + | |
| 358 | + | |
| 359 | + | |
| 360 | + | |
| 361 | + | |
| 362 | + | |
| 363 | + | |
| 364 | + | |
| 365 | + | |
| 366 | + | |
| 367 | + | |
| 368 | + | |
| 369 | + | |
| 370 | + | |
| 371 | + | |
| 372 | + | |
| 373 | + | |
| 374 | + | |
| 375 | + | |
| 376 | + | |
| 377 | + | |
| 378 | + | |
| 379 | + | |
| 380 | + | |
| 381 | + | |
| 382 | + | |
| 383 | + | |
| 384 | + | |
326 | 385 | | |
327 | 386 | | |
328 | 387 | | |
| |||
0 commit comments