element-hq / element-hq/element-meta
Allow saying "I am OK with user A impersonating me"
- Dominant language
- No language data
- Stars
- 112
- Forks
- 25
- Avg merge
- 6h 6m
- Merged PRs (30d)
- 4
Description
As described in https://github.com/element-hq/element-meta/issues/2950, some bridges create "ghost" users, who do not have cryptographic devices, and send messages from the bridge's device, "faking" the sender.
In #2950 we propose to allow this behaviour but make it clearly visible in the UI.
In this issue we propose to restrict this behaviour, so it is only possible if the ghost user explicitly publishes something saying "I am OK with user A impersonating me". Then clients can hide messages that fake senders if the sender in question has not published this thing.
Note: the solution should also work for "double-puppeted" users i.e. users who do have real devices, but have also given a bridge permission to speak on their behalf.
Design a cryptographically-secure mechanism of publishing this information ("I am OK with user A impersonating me").
Write an MSC proposing this mechanism.
Implement it in Element clients.
Contributor guide
No contributing guide indexed for this repository
Research direction
Read the linked #2950 proposal to understand the ghost-user and double-puppeting context. Design the cryptographically secure consent mechanism, document it in an MSC, and implement it in Element clients; done means all three requested pieces are covered.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100