matrix-org / matrix-org/matrix-spec
Even though we can't e2e encrypt state events, should we sign them?
Open
A-Client-Server
feature
- Dominant language
- HTML
- Stars
- 330
- Forks
- 150
- Avg merge
- 2h 21m
- Merged PRs (30d)
- 3
Description
To prevent server admins spoofing them in e2e rooms
Contributor guide
Research direction
No files, tests, or entry points are identified. First clarify the threat model and whether signing state events is intended as a Matrix protocol change; done would require a decided approach and corresponding specification updates.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100