v0.3.0
Replace single-hash broadcast key derivation with PBKDF2-SHA256 (100k iterations default, configurable via kdfIterations). Backward compatible with legacy single-hash messages. Added Security Model section to README.
Replace single-hash broadcast key derivation with PBKDF2-SHA256 (100k iterations default, configurable via kdfIterations). Backward compatible with legacy single-hash messages. Added Security Model section to README.