Lightning peers speak BOLT messages over an encrypted, authenticated transport. The ecosystem standardized on the Noise protocol framework, commonly the XK pattern, rather than inventing a bespoke handshake.
Why this matters
Channel state machines assume you are talking to the correct peer over a confidential link. Broken transport assumptions become fund-loss or privacy bugs.
What Noise buys you
Noise patterns compose Diffie–Hellman and symmetric crypto into documented handshakes with clear payload encryption rules. Lightning’s transport BOLT specifies how node static keys participate so peers authenticate identities as they set up sessions.
Builder rules
- Never roll your own handshake — use the implementation’s transport.
- Treat node pubkeys as identities; verify out-of-band when opening large channels.
- Separate clearnet exposure, Tor, and key backup OPSEC.
Common mistakes
- Pasting node URIs from untrusted chats without verifying the pubkey
- Logging session secrets or static keys
- Assuming LAN Lightning needs no auth because “it’s private”