element-hq / element-hq/element-meta

Allow saying "I am OK with user A impersonating me"

Open
#2,963 5 comments 0 reactions 0 assignees View on GitHub
Team: Crypto
Dominant language
No language data
Stars
112
Forks
25
Avg merge
6h 6m
Merged PRs (30d)
4

Description

As described in https://github.com/element-hq/element-meta/issues/2950, some bridges create "ghost" users, who do not have cryptographic devices, and send messages from the bridge's device, "faking" the sender.

In #2950 we propose to allow this behaviour but make it clearly visible in the UI.

In this issue we propose to restrict this behaviour, so it is only possible if the ghost user explicitly publishes something saying "I am OK with user A impersonating me". Then clients can hide messages that fake senders if the sender in question has not published this thing.

Note: the solution should also work for "double-puppeted" users i.e. users who do have real devices, but have also given a bridge permission to speak on their behalf.

Design a cryptographically-secure mechanism of publishing this information ("I am OK with user A impersonating me").

Write an MSC proposing this mechanism.

Implement it in Element clients.

Contributor guide

No contributing guide indexed for this repository

Research direction

Read the linked #2950 proposal to understand the ghost-user and double-puppeting context. Design the cryptographically secure consent mechanism, document it in an MSC, and implement it in Element clients; done means all three requested pieces are covered.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.