01 / My build
Read the frame,
then verify the message.
I implemented an 8-byte header, a 28-byte authentication block, typed body fields and a 64-byte Ed25519 signature. The server has registration, login, balance and transfer handlers and persists serialized state.
02 / Learning
Carrying a nonce
does not stop replays.
The packet format carries a session nonce and sequence number, but the current server does not enforce replay checks. The development client also accepts all TLS certificates. These implementation gaps must be closed before the transport can be described as secure.
03 / Current limits
Guarantees still
to define.
Canonical field ordering, account authorization, parser size bounds and persistence failures need further work. The reviewed repository has no structured build and no automated integration suite.
The packet sizes above describe the source format. A bandwidth comparison with JSON/HTTP would require a reproducible benchmark with equivalent payloads.
04 / Next steps
Make the boundaries
testable.
Enforce nonce and sequence checks, replace development TLS trust with certificate verification, add account-ownership checks and bound the parser. With a runnable client and adversarial tests, the protocol's behavior would be easier to demonstrate.