ECDSA on every packet
Digital signatures
Every message, image, and command is signed with ECDSA, in the same family of idea as an Ethereum transaction. You cannot send an unsigned Blackout Comms message.
The signed data covers sender, recipient, payload, send time, and metadata such as location. A relay cannot alter the body or the header and still have the signature check out. A fake or edited packet is dropped at the first device that sees it.
Private cluster
Messages are signed with the sender’s private key. Other devices already have, or can fetch, the matching public key, so the signature is checked at every hop. A relay can validate a direct message even though it cannot decrypt it.
Signed delivery confirmations
When a device validates a direct message meant for it, it signs a delivery confirmation and sends it back. The sender shows a checkmark only after that signed proof arrives. Green means a direct delivery. Blue means the message took at least two hops.
Open channels
Channels still hop, encrypt, and sign. They are “open” only in the sense that there is no constant pinging, no device cap, and joining takes the series of four channel passwords instead of an in-person root onboarding.
Broadcasts on a channel are signed and encrypted with the channel’s secret keys — four distinct symmetric keys. Any device on the channel checks the signature before it treats the message as valid or forwards it.