element-hq / element-hq/element-call

Sunset Shared Secred encryption option

Open
#3,188 0 comments 0 reactions 0 assignees View on GitHub
T-Enhancement
Dominant language
TypeScript
Stars
996
Forks
213
Avg merge
1d 6h
Merged PRs (30d)
54

Description

### Your use case

#### What would you like to do?
Remove all code that is related with Shared Secred encryption.
#### Why would you like to do it?
If to-device key exchange is performant enough to support large calls this would simplify our codebase and make calls more secure.
#### How would you like to achieve it?
Draft a strategy on how we can leave shared secret encryption. We would need a way to verify users. The invite link would need to contain a join secret so we have an actually more secure system.

### Have you considered any alternatives?

Keep shared secret as a long term solution and continue maintaining it.

### Additional context

_No response_

Contributor guide

Open the contributing guide

Research direction

Start by mapping all code and entry points related to Shared Secret encryption, then review how to-device key exchange currently supports calls. Draft the removal strategy, including user verification and a join secret in invite links; done means the strategy clearly defines the code to remove and the more secure replacement requirements.

Written by the indexing model from the issue text.

Assessment

Tech stack
typescript
Domain
security
Issue type
Refactor
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.