matrix-org / matrix-org/matrix-hookshot

Hookshot doesn't verify it's devices

Open
#1,001 12 comments 5 reactions 0 assignees View on GitHub
E2EE S-Major T-Task
Dominant language
TypeScript
Stars
450
Forks
95
Avg merge
1d 2h
Merged PRs (30d)
23

Description

This generates red warning on all it's encrypted messages

![screenshot_2024-12-11T14-19-15Z](https://github.com/user-attachments/assets/09150c6c-6f25-4bda-be5a-12e806497ab1)

![screenshot_2024-12-11T14-19-41Z](https://github.com/user-attachments/assets/a20683f2-aed8-4539-898a-168f15535aba)

And E2EE Hookshot will stop working entirely once [MSC4153: Exclude non-cross-signed devices](https://github.com/matrix-org/matrix-spec-proposals/pull/4153) gets implemented.

Contributor guide

Open the contributing guide

Research direction

Start by reproducing the red warning on encrypted messages in E2EE Hookshot and review the device-verification flow. Compare its behavior with MSC4153, then verify that encrypted messages no longer warn and that E2EE Hookshot continues working when non-cross-signed devices are excluded.

Written by the indexing model from the issue text.

Assessment

Tech stack
typescript
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.