element-hq / element-hq/element-call
Sunset Shared Secred encryption option
- Dominant language
- TypeScript
- Stars
- 996
- Forks
- 213
- Avg merge
- 1d 6h
- Merged PRs (30d)
- 54
Description
### Your use case
#### What would you like to do?
Remove all code that is related with Shared Secred encryption.
#### Why would you like to do it?
If to-device key exchange is performant enough to support large calls this would simplify our codebase and make calls more secure.
#### How would you like to achieve it?
Draft a strategy on how we can leave shared secret encryption. We would need a way to verify users. The invite link would need to contain a join secret so we have an actually more secure system.
### Have you considered any alternatives?
Keep shared secret as a long term solution and continue maintaining it.
### Additional context
_No response_
Contributor guide
Research direction
Start by mapping all code and entry points related to Shared Secret encryption, then review how to-device key exchange currently supports calls. Draft the removal strategy, including user verification and a join secret in invite links; done means the strategy clearly defines the code to remove and the more secure replacement requirements.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- typescript
- Domain
- security
- Issue type
- Refactor
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100