throneless-tech / throneless-tech/bitpart
Security concerns over Signal linking
Nobody has claimed this yet.
- Dominant language
- Rust
- Stars
- 38
- Forks
- 1
- PR merge metrics
- No merged PRs in 30d
Description
Is your feature request related to a problem? Please describe.
SECURITY ISSUE
3 testers (1 technical, 2 info sec) had concerns about linking Signal. For 2 the main concern was that QR code & device linking has been used to phish. For an early tester, they were surprised that this is how it worked and wanted to know that a QR code was used earlier, before they went to the trouble of making their bot. (We added in more language / clarity already to resolve this, in Choose your Bot page)
Tester 2: "I would be concerned with this step. I don't want Signal connected to another device that i don't control. For me to use this as a helpdesk, tipline, etc, I would want a signal account just for this. But there is a lot of trust between me and bitpart. I have to be very well informed about how secure are bitpart servers, what are the measures."
It's worth noting that other tests were comfortable with this. e.g.
Tester 8: " I've seen similar things with Matrix, to connect to Signal
Tester 11: "It's like activating whatsapp web."
Describe the solution you'd like
A way for users to check how many devices are linked or connected to their bot number (such as in the dashboard)
OR if not possible,
Security reminders for bot creators to check their Signal & check how many devices are linked to their bot number.
Additional context: Does this feature request require changes to the Bitpart server or EMS?
Add any other context or screenshots about the feature request here.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No files, tests, or entry points are named. First clarify whether the work should provide a dashboard device count or reminders for bot creators, then determine what Signal linking information Bitpart can expose; done means users can reliably check or understand the linked-device security state.
Written by the indexing model from the issue text.
Assessment
- Domain
- security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100