pull down to refresh

Maybe the connect request doesn't need encryption, only signatures from client+server. It's not the request that is sensitive, but the response.

Can you elaborate this?

reply

The response will include credentials to spend, so the server shouldn’t be able to send the request and get a response

reply
Sorry for the wallet of text.

A+

reply