matrix-org / matrix-org/matrix-spec

Even though we can't e2e encrypt state events, should we sign them?

Open
#227 1 comment 3 reactions 0 assignees View on GitHub
A-Client-Server feature
Dominant language
HTML
Stars
330
Forks
150
Avg merge
2h 21m
Merged PRs (30d)
3

Description

To prevent server admins spoofing them in e2e rooms

Contributor guide

Open the contributing guide

Research direction

No files, tests, or entry points are identified. First clarify the threat model and whether signing state events is intended as a Matrix protocol change; done would require a decided approach and corresponding specification updates.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.