element-hq / element-hq/element-meta
Configurable E2E trust levels per room (and globally)
- Dominant language
- No language data
- Stars
- 112
- Forks
- 25
- Avg merge
- 6h 6m
- Merged PRs (30d)
- 4
Description
A nice improvement before we have nailed device cross-signing (https://github.com/vector-im/riot-web/issues/2714) would be to let users simply state whether in a given room (or across their whole account) they should actually care about verifying remote devices or not. For some use cases users may legitimately just not care about checking the identity of whoever they're speaking to; they just want to ensure their server admin can't trivially read their logs.
I'm slightly worried that this may train users into just ignoring all the security checks, but it's probably desirable until we have cross-signing sorted. @lampholder has suggestions for a design in the "Global/local E2E settings" section of https://docs.google.com/document/d/12r21OrXYEvzKclKCUWX2a-2ckU6Se0IJHoZaLicVxFc and the idea of just having a badge appear on the padlock when the dashboard wants to warn you about an unverified device (but doesn't block your messages in an low-trust room) seems like a relatively okay compromise.
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by reading the “Global/local E2E settings” section of the linked Google document and the related cross-signing issue. Use those materials to determine the intended global and per-room trust behavior and the warning treatment; the issue is complete only when that design and its implementation scope are agreed.
Written by the indexing model from the issue text.
Assessment
- Domain
- security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100