element-hq / element-hq/element-android

Cross-device signing is messed up

Open
#2,426 0 comments 3 reactions 0 assignees View on GitHub
Dominant language
Kotlin
Stars
3.7k
Forks
917
PR merge metrics
No merged PRs in 30d

Description

**Describe the bug**
I have cross-device signing set up correctly. I had a chat with another user who had set up cross-device signing, but l had access only to a phone at the moment which wasn't verified. He didn't set up SSSS, because it weakens the strength of Megolm. Although the settings said that cross-device signing is enabled, but keys are not found, he started verification. We compared the emojis, and selected OK. Then it got messed up. It showed a **green** shield in my timeline saying "Verified!" but the room decoration was **black**, and he said when he checked his devices in Settings, he had a **red** device (maybe his current session which weren't verified).

**To Reproduce**
Steps to reproduce the behavior:
1. Have an account with fully setup and verified cross-device signing
2. Have an account with an unverified device
3. Start verification from the unverified device
4. When verification is successfully finished, it's a mess

**Expected behavior**
- Not being able to verify from an unverified device or
- If access is lost to the other sessions, **be able to reset the master key from Element Android**
- Not indicating false values on shield decoration

**Screenshots**
![kép](https://user-images.githubusercontent.com/26059643/99718946-930bec00-2aa3-11eb-9bff-b9a1c518d8c5.png)

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.