Skip to content

Release v0.2.0 - CRITICAL SECURITY FIX: Per-Account Encryption

Choose a tag to compare

@blocksorg blocksorg released this 04 Nov 00:57
· 20 commits to main since this release

MigChat CLI v0.2.0 - CRITICAL SECURITY FIX

πŸ”΄ CRITICAL: Per-Account Encryption Keys

This is a major security release that fixes a critical vulnerability where all accounts shared the same encryption keys.

Security Issue Fixed

Severity: CRITICAL πŸ”΄
CVE: N/A (internal discovery)
Affects: v0.1.8, v0.1.9

All user accounts on the same machine were sharing identical encryption keys, meaning:

  • ❌ All accounts had the same fingerprint
  • ❌ Any account could decrypt messages meant for other accounts
  • ❌ Key verification was meaningless (all verified the same key)
  • ❌ If one account was compromised, ALL accounts were compromised

Solution

Each account now has unique encryption keys stored separately:

Before (INSECURE):

~/.config/migchat/keys/           # ❌ Shared by ALL accounts
  β”œβ”€β”€ identity_key.enc
  └── signed_prekey.enc

After (SECURE):

~/.config/migchat/keys/
  β”œβ”€β”€ alice/                      # βœ… Alice's unique keys
  β”‚   β”œβ”€β”€ identity_key.enc
  β”‚   └── signed_prekey.enc
  └── bob/                        # βœ… Bob's unique keys
      β”œβ”€β”€ identity_key.enc
      └── signed_prekey.enc

πŸ”’ What's Fixed

Per-Account Encryption

  • βœ… Each account has unique encryption keys
  • βœ… Keys stored in ~/.config/migchat/keys/{username}/
  • βœ… Sessions isolated per account: ~/.config/migchat/sessions/{username}/
  • βœ… Different accounts have different fingerprints
  • βœ… Account isolation enforced
  • βœ… Multi-account setup is now secure

Architecture Changes

Core Crypto Modules:

  • Added EncryptionManager::for_account(username) method
  • Added KeyManager::for_account(username) method
  • Added SessionManager::for_account(username) method

UI Updates:

  • Changed encryption: EncryptionManager β†’ Option<EncryptionManager>
  • Encryption manager switches when switching accounts
  • Account-specific initialization on login/creation
  • Safe access via ensure_encryption() helpers

πŸ“ Changes

Security Fixes

  • [CRITICAL] Per-account encryption keys (#9, #10)
  • [CRITICAL] Account isolation for encryption sessions

Bug Fixes

  • Fixed compilation errors in encryption implementation
  • Fixed borrow checker issues with token handling
  • Fixed type mismatches in API method calls

Commits Since v0.1.9

  • 21bf295: Complete per-account encryption implementation
  • 3aa5543: Fix compilation errors in per-account encryption
  • f8b271a: Fix all remaining compilation errors
  • b4db547: Bump version to 0.2.0

Full Changelog: v0.1.9...v0.2.0

🚨 Action Required for Existing Users

Single-Account Users

  • βœ… No action needed - Your setup will continue to work
  • Your keys will remain in the default location

Multi-Account Users

  • ⚠️ Important: Your old accounts may have been using shared keys
  • Recommended Actions:
    1. Download the new v0.2.0 binary
    2. Log into each account
    3. Generate new keys (log out and log back in)
    4. Verify your new fingerprints with contacts
    5. Consider rotating keys if you suspect compromise

Migration Details

First account to log in:

  • May retain old global keys (backward compatible)

Subsequent accounts:

  • Will generate new unique keys automatically

Best Practice:

  • Regenerate keys for all accounts to ensure proper isolation
  • Verify fingerprints with all contacts after upgrade

πŸ” Security Best Practices

After upgrading:

  1. βœ… Log out and log back into each account to ensure keys are per-account
  2. βœ… View your fingerprint (Security β†’ View My Fingerprint)
  3. βœ… Verify it's different for each account
  4. βœ… Share new fingerprints with your contacts
  5. βœ… Have contacts verify your new fingerprints

πŸ“Š Testing

Verified functionality:

  • βœ… Each account generates unique keys
  • βœ… Different accounts have different fingerprints
  • βœ… Account isolation enforced
  • βœ… Multi-account encryption works securely
  • βœ… Backward compatibility with single-account setups
  • βœ… All builds passing on all platforms

πŸ›‘οΈ Security Properties

Before v0.2.0

  • πŸ”΄ Shared keys across all accounts
  • πŸ”΄ No account isolation
  • πŸ”΄ Compromised security model

v0.2.0 and Later

  • βœ… Unique keys per account
  • βœ… Full account isolation
  • βœ… Secure multi-account support
  • βœ… Proper fingerprint verification
  • βœ… Forward secrecy maintained

πŸ“¦ Installation

Upgrading from v0.1.x:

  1. Download the new binary for your platform
  2. Replace your existing binary
  3. Important: Log out and log back in to each account

Quick Install (Linux/macOS):

curl -fsSL https://raw.githubusercontent.com/migchat/cli/main/install.sh | bash

Quick Install (Windows):

irm https://raw.githubusercontent.com/migchat/cli/main/install.ps1 | iex

πŸ”— Related Issues

  • Closes #9: CRITICAL: All accounts share the same encryption keys
  • PR #10: Per-account encryption implementation

Priority: P0 - Critical Security Fix
Type: Security, Breaking Change (internal)
Impact: All users with multiple accounts
Recommendation: Upgrade immediately if using multiple accounts