matrix-org / matrix-org/matrix-spec
Cross-signing leaks metadata to the server about who trusts who.
Open
A-E2EE
feature
security
- Dominant language
- HTML
- Stars
- 330
- Forks
- 150
- Avg merge
- 2h 21m
- Merged PRs (30d)
- 3
Description
We should encrypt the cross-signing attestations given the server has no business seeing what users have verified each other.
Contributor guide
Research direction
No files, tests, or entry points are named. Start by reviewing the cross-signing attestation protocol and its threat model; done would require an agreed specification change that prevents the server from learning who has verified whom.
Written by the indexing model from the issue text.
Assessment
- Domain
- cryptography, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100