element-hq / element-hq/element-android

Senders could resend megolm keys to new verified devices #15160

Open
#2,102 0 comments 0 reactions 0 assignees View on GitHub
A-E2EE A-E2EE-Cross-Signing T-Enhancement
Dominant language
Kotlin
Stars
3.7k
Forks
917
PR merge metrics
No merged PRs in 30d

Description

#See https://github.com/vector-im/element-meta/issues/1888

> Now we have cross-signing, another mechanism to prevent UISIs could be for senders to resend megolm keys for conversations to new devices if they are verified (or respond to keyshare reqs for said keys). This means that even if the new device doesn't have online backup, and can't request the keys from the user's other devices, they can request them from the sender

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.