element-hq / element-hq/element-meta

Improve UX of E2EE-initialization

Open
#498 1 comment 7 reactions 0 assignees View on GitHub
A-E2EE App: Android App: iOS App: web O-Frequent S-Major T-Enhancement T-Epic Team: Crypto
Dominant language
No language data
Stars
112
Forks
25
Avg merge
6h 6m
Merged PRs (30d)
4

Description

**Problem**
I had to aid many users in setting up Element, because they have trouble understanding what happens during E2EE backup creation \(and, in the worst case, gave up frustrated or lost their E2EE-key right away after "trying out" Element, aborting the backup process and losing their initial session\).
I observed the following challenges \(for non-technical users\):
- Users don't understand why they need to create a backup when setting up a messenger and are therefore likely to abort the dialog
- Users don't understand the difference between a "security key" and a "security phrase" \(and often have no concept whatsoever of things like "keys", "encryption", "cryptography" or "E2EE"\).

**Describe the solution you'd like**
Streamline the E2EE backup, so that there is **one** easy-to-use and recommended option and move the alternatives to an "advanced" section.
I would recommend to offer the security key as default, because in my experience, many users confuse the backup passphrase with their account password and don't know which to use in which context.

**Additional thoughts**

- \~Encrypted backup keys could be synced over the home server \(protected by a password\) or various cloud providers could be supported for uploading backups.\~ This might already be the status quo. I'm not sure if I understand the dialog correctly...
- Clearly state that the "security key" is a text file \(and suggest users to print it, at least on web/desktop\)

Contributor guide

No contributing guide indexed for this repository

Research direction

The issue names no files, tests, or specific client entry points. Start by reviewing the E2EE backup-creation dialog during Element setup, including the web and desktop experiences. Done should mean one recommended option, alternatives grouped as advanced, and clear explanations of the security key, security phrase, and printing or storing the key.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.