Join GitHub today
GitHub is home to over 28 million developers working together to host and review code, manage projects, and build software together.
Sign upOption to only send encrypted messages to verified devices #2313
Comments
richvdh
added
cosmetic
type:e2e
and removed
cosmetic
labels
Sep 20, 2016
richvdh
added
feature
p2
major
labels
Oct 31, 2016
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
vext01
Nov 25, 2016
We've just discussed this very issue.
It worries me that an unverified party can silently intercept encrypted messages undetected.
vext01
commented
Nov 25, 2016
|
We've just discussed this very issue. It worries me that an unverified party can silently intercept encrypted messages undetected. |
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
vext01
commented
Nov 25, 2016
|
And this is not a bug unique to vector-web |
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
ArdaXi
Nov 25, 2016
I would suggest having this per-user. Primarily because it empowers the user to increase security for their own messages without having to have the necessary room privileges.
Would be nice if this were supported for the entire room as well, but that's a Matrix spec issue too.
ArdaXi
commented
Nov 25, 2016
|
I would suggest having this per-user. Primarily because it empowers the user to increase security for their own messages without having to have the necessary room privileges. Would be nice if this were supported for the entire room as well, but that's a Matrix spec issue too. |
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
ara4n
Dec 22, 2016
Member
Just to confirm: this is very much on our radar, but we're also having to juggle all other issues coughed up by the beta - i.e. the Unknown Inbound Session ID bugs, verifying devices, and giving folks the ability to backup & restore E2E state. It will be coming RSN, and yes, it does pose a serious issue (as do the others).
|
Just to confirm: this is very much on our radar, but we're also having to juggle all other issues coughed up by the beta - i.e. the Unknown Inbound Session ID bugs, verifying devices, and giving folks the ability to backup & restore E2E state. It will be coming RSN, and yes, it does pose a serious issue (as do the others). |
ara4n
added
p1
and removed
p2
labels
Dec 28, 2016
richvdh
referenced this issue
Jan 6, 2017
Closed
Option to disable automatically trusting new devices. #2843
This was referenced Jan 22, 2017
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
|
i did this. |
richvdh commentedSep 20, 2016
Probably at the per-room level. Shared across all users, or per-user?