throneless-tech / throneless-tech/bitpart

Security concerns over Signal linking

Open
#18 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

flagged in testing needs discussion
Dominant language
Rust
Stars
38
Forks
1
PR merge metrics
No merged PRs in 30d

Description

Is your feature request related to a problem? Please describe.
SECURITY ISSUE
3 testers (1 technical, 2 info sec) had concerns about linking Signal. For 2 the main concern was that QR code & device linking has been used to phish. For an early tester, they were surprised that this is how it worked and wanted to know that a QR code was used earlier, before they went to the trouble of making their bot. (We added in more language / clarity already to resolve this, in Choose your Bot page)

Tester 2: "I would be concerned with this step. I don't want Signal connected to another device that i don't control. For me to use this as a helpdesk, tipline, etc, I would want a signal account just for this. But there is a lot of trust between me and bitpart. I have to be very well informed about how secure are bitpart servers, what are the measures."

It's worth noting that other tests were comfortable with this. e.g.
Tester 8: " I've seen similar things with Matrix, to connect to Signal
Tester 11: "It's like activating whatsapp web."

Describe the solution you'd like
A way for users to check how many devices are linked or connected to their bot number (such as in the dashboard)
OR if not possible,
Security reminders for bot creators to check their Signal & check how many devices are linked to their bot number.

Additional context: Does this feature request require changes to the Bitpart server or EMS?
Add any other context or screenshots about the feature request here.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No files, tests, or entry points are named. First clarify whether the work should provide a dashboard device count or reminders for bot creators, then determine what Signal linking information Bitpart can expose; done means users can reliably check or understand the linked-device security state.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.