element-hq / element-hq/element-android
Cross-device signing is messed up
- Dominant language
- Kotlin
- Stars
- 3.7k
- Forks
- 917
- PR merge metrics
- No merged PRs in 30d
Description
**Describe the bug**
I have cross-device signing set up correctly. I had a chat with another user who had set up cross-device signing, but l had access only to a phone at the moment which wasn't verified. He didn't set up SSSS, because it weakens the strength of Megolm. Although the settings said that cross-device signing is enabled, but keys are not found, he started verification. We compared the emojis, and selected OK. Then it got messed up. It showed a **green** shield in my timeline saying "Verified!" but the room decoration was **black**, and he said when he checked his devices in Settings, he had a **red** device (maybe his current session which weren't verified).
**To Reproduce**
Steps to reproduce the behavior:
1. Have an account with fully setup and verified cross-device signing
2. Have an account with an unverified device
3. Start verification from the unverified device
4. When verification is successfully finished, it's a mess
**Expected behavior**
- Not being able to verify from an unverified device or
- If access is lost to the other sessions, **be able to reset the master key from Element Android**
- Not indicating false values on shield decoration
**Screenshots**

Contributor guide
Assessment
This issue has not been assessed yet.