element-hq / element-hq/element-meta

Security terminology

Open
#361 11 comments 8 reactions 0 assignees View on GitHub
A-Documentation A-E2EE T-Defect X-Needs-Design
Dominant language
No language data
Stars
112
Forks
26
Avg merge
6h 6m
Merged PRs (30d)
4

Description

I would like to break this down into smaller bugs, but I'm afraid I can't because I have not at all understood what is what myself. I'm only fairly confident that the amount of different terms exceeds the number of actual concepts used here, so this needs a cleanup. I am at a complete loss as to what this cleanup would look like.

The following summarizes the non-selfexplanatory (even for someone familiar with assymetric encryption, but much less so for an average user) terms that are mentioned on the *Security & Privacy* dialog alone.

- Session ID
- Verify User
- Verify Session
- Secure Backup
- Encryption Keys
- Recovery Key
- Backup key
- Secret Storage
- Security Passphase
- Backup
- Signature
- Cross-signing
- Cross-signing Key
- Master (Private) Key
- Self-signing (Private) Key
- User-signing (Private) Key
- Session Key
- Security Key

Particularly confusing is the mention of the three "private-only" keys and the remark that something called a "Backup Key" has been stored in "Secret Storage" (which perhaps could be the "Secure Backup").

I hope, if you are a developer, you can appreciate just *how* confusing this is for anyone who was not involved in designing it. I have mentioned a couple of terms which are clear to me (e.g. "Session ID"), but I think the gist of it should be that the terms are given names of concepts which can be understood without detailled, technical insight. I would speculate that it boils down to approximately (where KP = Key pair), at least that's what I could make sense of:

- Per-Session-KP / Per-Device-KP
- Account KP (a.k.a. "Cross-Signing Key")
- Backup Key

Contributor guide

No contributing guide indexed for this repository

Research direction

Start with the Security & Privacy dialog and inventory the listed terms, especially the three private-only keys and the Backup Key stored in Secret Storage. Compare each label with the concepts it describes and seek agreement on a smaller, user-understandable vocabulary; done means the terminology and relationships are clearly defined.

Written by the indexing model from the issue text.

Assessment

Tech stack
cryptography
Domain
security
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.