element-hq / element-hq/element-meta

Suggestion/discussion: E2E practicability in social rooms / missing "Enable URL previews by default" for E2E rooms setting and its impact

Open
#288 9 comments 6 reactions 0 assignees View on GitHub
Privacy T-Enhancement X-Needs-Product
Dominant language
No language data
Stars
112
Forks
25
Avg merge
6h 6m
Merged PRs (30d)
4

Description

Sorry that I am proposing this in such an essay, but I am expecting this to be somewhat controversial but it is somewhat important to me:

Currently, I feel like there is a somewhat notable incentive to never enable E2E for any social non-super-private rooms if non-techies are in it. That makes me sad, I want encryption to be everywhere where it is practical, and it feels like here it could also be with minor changes.

The reason social hangouts clash with E2E is that the link preview will automatically be broken with `"Enable URL previews by default for participants in this room"` unavailable/forced off. And I get that it'd default to Off, but it being entirely unchangeable for room admins poses a problem: some rooms are just fun social hang outs, and if regular users (like, imagine WhatsApp crowd coming over, and shouldn't that be great?) need to poke in the settings for such a basic feature, some users will likely just move on. And you can blame or not blame them for that, but the result is that it makes an E2E setup way less practical for more casual non-techie social rooms.

And here I get you could argue why even enable E2E then? Also, wouldn't letting room admins mess with this default risk security-conscious people unintentionally exposing themselves to a spying homeserver? Obviously it's a trade-off, but maybe think of it like this: it's still more secure to have an E2E room where link previews are enabled for regular unaware users by default (which they can still opt-out of!) than to have an unencrypted room entirely. And if gif previews are always, unchangeably opt-in even for fun social rooms, the truth is just many of these places won't enable E2E which is a total loss of security in numbers. It turns enabling E2E for a room admin from a no-brainer (outside of corner cases like bridges) to a difficult decision in some cases.

I am therefore proposing the following combined changes for discussion to balance this difficult situation:

- Step 1: Reintroduce `Enable URL previews by default for participants in this room` for room admins of encrypted rooms, but default it to off
- Step 2: Introduce a new user setting `Override URL preview in encrypted rooms to off, no matter the room's default` that defaults to off

And yes, I realize more settings is bad, and some people will miss both the per-channel opt-out and the new global opt-out and have links leaked when they thought they wouldn't be. I do realize many security hardliners will not like this. But I hope that you find it worth at least debating, in a possible future where hopefully E2E can reach everyone and their families, and security-conscious people can still find themselves at least somewhat sufficiently empowered to deviate and override to the defaults they want if they don't like how things are set by default. And I agree this isn't ideal, but neither does the current situation seem to be.

I am looking forward to your input!

Contributor guide

No contributing guide indexed for this repository

Research direction

The issue names no files, tests, or entry points. Start by reading the nine-comment discussion and tracing the existing encrypted-room URL-preview settings in the relevant Element client. Done requires a settled decision on the two proposed settings, their defaults, and override behavior.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.