Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Messages posted prior to enabling id blinding are downloaded with real Session id after enabling id blinding. #164

Closed
ianmacd opened this issue Jan 2, 2023 · 2 comments

Comments

@ianmacd
Copy link
Contributor

ianmacd commented Jan 2, 2023

After enabling id blinding on sog.caliban.org, I observe that messages posted prior to blinding are still downloaded by Session with the original unblinded id.

This allows the association of blinded ids with their unblinded counterparts for any given display name.

Should id blinding not be retroactively applied to all messages downloaded from the server?

@jagerman
Copy link
Member

jagerman commented Jan 2, 2023

Unfortunately it cannot be done retroactively because clients need to be able to verify the signature of the message (i.e. they do not have to trust SOGS as to the content of a message), but those signatures will be invalid if the poster ID is changed.

@ianmacd
Copy link
Contributor Author

ianmacd commented Jan 2, 2023

Unfortunately it cannot be done retroactively because clients need to be able to verify the signature of the message (i.e. they do not have to trust SOGS as to the content of a message), but those signatures will be invalid if the poster ID is changed.

Understood. Thank you.

@ianmacd ianmacd closed this as completed Jan 2, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants