element-hq / element-hq/element-meta

Configurable E2E trust levels per room (and globally)

Open
#1,271 1 comment 1 reaction 0 assignees View on GitHub
A-E2EE P1 T-Enhancement
Dominant language
No language data
Stars
112
Forks
25
Avg merge
6h 6m
Merged PRs (30d)
4

Description

A nice improvement before we have nailed device cross-signing (https://github.com/vector-im/riot-web/issues/2714) would be to let users simply state whether in a given room (or across their whole account) they should actually care about verifying remote devices or not. For some use cases users may legitimately just not care about checking the identity of whoever they're speaking to; they just want to ensure their server admin can't trivially read their logs.

I'm slightly worried that this may train users into just ignoring all the security checks, but it's probably desirable until we have cross-signing sorted. @lampholder has suggestions for a design in the "Global/local E2E settings" section of https://docs.google.com/document/d/12r21OrXYEvzKclKCUWX2a-2ckU6Se0IJHoZaLicVxFc and the idea of just having a badge appear on the padlock when the dashboard wants to warn you about an unverified device (but doesn't block your messages in an low-trust room) seems like a relatively okay compromise.

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reading the “Global/local E2E settings” section of the linked Google document and the related cross-signing issue. Use those materials to determine the intended global and per-room trust behavior and the warning treatment; the issue is complete only when that design and its implementation scope are agreed.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.