Release v0.2.0 - CRITICAL SECURITY FIX: Per-Account Encryption
MigChat CLI v0.2.0 - CRITICAL SECURITY FIX
π΄ CRITICAL: Per-Account Encryption Keys
This is a major security release that fixes a critical vulnerability where all accounts shared the same encryption keys.
Security Issue Fixed
Severity: CRITICAL π΄
CVE: N/A (internal discovery)
Affects: v0.1.8, v0.1.9
All user accounts on the same machine were sharing identical encryption keys, meaning:
- β All accounts had the same fingerprint
- β Any account could decrypt messages meant for other accounts
- β Key verification was meaningless (all verified the same key)
- β If one account was compromised, ALL accounts were compromised
Solution
Each account now has unique encryption keys stored separately:
Before (INSECURE):
~/.config/migchat/keys/ # β Shared by ALL accounts
βββ identity_key.enc
βββ signed_prekey.enc
After (SECURE):
~/.config/migchat/keys/
βββ alice/ # β
Alice's unique keys
β βββ identity_key.enc
β βββ signed_prekey.enc
βββ bob/ # β
Bob's unique keys
βββ identity_key.enc
βββ signed_prekey.enc
π What's Fixed
Per-Account Encryption
- β Each account has unique encryption keys
- β
Keys stored in
~/.config/migchat/keys/{username}/ - β
Sessions isolated per account:
~/.config/migchat/sessions/{username}/ - β Different accounts have different fingerprints
- β Account isolation enforced
- β Multi-account setup is now secure
Architecture Changes
Core Crypto Modules:
- Added
EncryptionManager::for_account(username)method - Added
KeyManager::for_account(username)method - Added
SessionManager::for_account(username)method
UI Updates:
- Changed
encryption: EncryptionManagerβOption<EncryptionManager> - Encryption manager switches when switching accounts
- Account-specific initialization on login/creation
- Safe access via
ensure_encryption()helpers
π Changes
Security Fixes
- [CRITICAL] Per-account encryption keys (#9, #10)
- [CRITICAL] Account isolation for encryption sessions
Bug Fixes
- Fixed compilation errors in encryption implementation
- Fixed borrow checker issues with token handling
- Fixed type mismatches in API method calls
Commits Since v0.1.9
21bf295: Complete per-account encryption implementation3aa5543: Fix compilation errors in per-account encryptionf8b271a: Fix all remaining compilation errorsb4db547: Bump version to 0.2.0
Full Changelog: v0.1.9...v0.2.0
π¨ Action Required for Existing Users
Single-Account Users
- β No action needed - Your setup will continue to work
- Your keys will remain in the default location
Multi-Account Users
β οΈ Important: Your old accounts may have been using shared keys- Recommended Actions:
- Download the new v0.2.0 binary
- Log into each account
- Generate new keys (log out and log back in)
- Verify your new fingerprints with contacts
- Consider rotating keys if you suspect compromise
Migration Details
First account to log in:
- May retain old global keys (backward compatible)
Subsequent accounts:
- Will generate new unique keys automatically
Best Practice:
- Regenerate keys for all accounts to ensure proper isolation
- Verify fingerprints with all contacts after upgrade
π Security Best Practices
After upgrading:
- β Log out and log back into each account to ensure keys are per-account
- β View your fingerprint (Security β View My Fingerprint)
- β Verify it's different for each account
- β Share new fingerprints with your contacts
- β Have contacts verify your new fingerprints
π Testing
Verified functionality:
- β Each account generates unique keys
- β Different accounts have different fingerprints
- β Account isolation enforced
- β Multi-account encryption works securely
- β Backward compatibility with single-account setups
- β All builds passing on all platforms
π‘οΈ Security Properties
Before v0.2.0
- π΄ Shared keys across all accounts
- π΄ No account isolation
- π΄ Compromised security model
v0.2.0 and Later
- β Unique keys per account
- β Full account isolation
- β Secure multi-account support
- β Proper fingerprint verification
- β Forward secrecy maintained
π¦ Installation
Upgrading from v0.1.x:
- Download the new binary for your platform
- Replace your existing binary
- Important: Log out and log back in to each account
Quick Install (Linux/macOS):
curl -fsSL https://raw.githubusercontent.com/migchat/cli/main/install.sh | bashQuick Install (Windows):
irm https://raw.githubusercontent.com/migchat/cli/main/install.ps1 | iexπ Related Issues
- Closes #9: CRITICAL: All accounts share the same encryption keys
- PR #10: Per-account encryption implementation
Priority: P0 - Critical Security Fix
Type: Security, Breaking Change (internal)
Impact: All users with multiple accounts
Recommendation: Upgrade immediately if using multiple accounts