element-hq / element-hq/element-meta

Backup Has A Signature From Unknown Device After Removing Devices

Open
#1,606 3 comments 1 reaction 0 assignees View on GitHub
P1 T-Defect
Dominant language
No language data
Stars
112
Forks
25
Avg merge
6h 6m
Merged PRs (30d)
4

Description

### Description

Due to the recent server intrusion, I had two "old" devices on my account that I removed since they're no longer linked to valid devices. However, because I had restored from server backup, I'm stuck with this message indefinitely: "Backup has a signature from unknown device". I also see warning symbols on all my old encrypted messages from before the server intrusion (though they are readable). They all say "encrypted by an unverified device". I'm hesitantly okay with the latter, since technically once a device is no longer on the account it can't be verified, but the key backup issue seems like it would leave that message there indefinitely. If the signatures from unknown devices are made removable from backup somehow, would that make all old encrypted messages unreadable? Or would that only affect the ability of prior (now non-existent) devices to read encrypted messages?

### Steps to reproduce

- Send encrypted messages using one device
- Use key backup
- Restore from backup on another device
- Remove device number 1 from account
- Messages sent from device number 1 will be marked as "unknown device"
- Key backup will say "Backup has a signature from unknown device"

Log: N/A

### Version information

- **Platform**: All Platforms

For the desktop app:

- **OS**: Windows 7 64-bit
- **Version**: 1.0.8

Contributor guide

No contributing guide indexed for this repository

Research direction

No repository files or tests are named. Start by reproducing the sequence of restoring key backup, removing the original device, and checking the backup warning and message verification state. Done should define and implement the expected handling of signatures from removed devices without unexpectedly making existing encrypted messages unreadable.

Written by the indexing model from the issue text.

Assessment

Tech stack
cryptography
Domain
cryptography, security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.