matrix-org / matrix-org/matrix-spec

Alternative/additional verification methods

Open
#1,203 2 comments 1 reaction 0 assignees View on GitHub
A-E2EE feature
Dominant language
HTML
Stars
330
Forks
150
Avg merge
2h 21m
Merged PRs (30d)
3

Description

When talking to other people, trying to convince them to use Matrix/Element, the verification process is always declared as being too complicated. I would therefor like to propose two alternative (or even complementing), opt-in verification methods:

The first one would simply be TOFU (Trust On First Use): In many cases I have seen, peers first talked to each other about opening a personal chat in Matrix, so that it's clear who the other person is when an invitation arrives. So the other end could simply accept that invitation w/o further verification.

The other method would be a (probably anonymized, hidden) web of trust (WoT). Given that A and B, as well as B and C already know (have verified) each other, A and C could verify each other by asking their common contact B (eventually w/o telling them who the common contact is) under the hood. The more common contacts can be asked, the better. Of course, the common contact(s) should have enabled WoT, too.

Users should then have the choice of enabling WoT with either TOFU or the traditional verification method being the fallback in case no common contacts are found.

Thoughts?

Contributor guide

Open the contributing guide

Research direction

Start by reviewing the existing Matrix verification process and the two proposed alternatives in this issue. Determine whether TOFU or a web of trust belongs in the Matrix specification, what protocol behavior would need to be defined, and what a concrete, agreed scope would be before implementation.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.