element-hq / element-hq/element-ios

Doesn't check entered recovery key is correct before attempting to decrypt secrets

Open
#8,010 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Swift
Stars
1.8k
Forks
544
PR merge metrics
PR metrics pending

Description

Eyeballing the code in `MatrixSDK/Crypto/Recovery/MXRecoveryService.m` and `MatrixSDK/Crypto/SecretStorage/MXSecretStorage.m`, and looking at a rageshake, it looks very much as though we don't validate the entered recovery key against the `mac` stored in `m.secret_storage.key.[key ID]` (see https://spec.matrix.org/v1.17/client-server-api/#key-storage).

This means that error reporting to the user is confusing: rather than saying "this is the wrong key", we have much more obscure errors. (Or, in fact, none at all, because it just loops back to "verify your account").

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.