Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Online key backup breaks after changing password? #9434

Open
ara4n opened this issue Apr 12, 2019 · 12 comments
Open

Online key backup breaks after changing password? #9434

ara4n opened this issue Apr 12, 2019 · 12 comments

Comments

@ara4n
Copy link
Member

ara4n commented Apr 12, 2019

I changed my password; after refreshing, the app claimed to be doing online key backup but empirically none of my history was visible.

This is going to break things massively for people after being told to reset passwords after security incident.....

@ara4n ara4n added T-Defect S-Critical Prevents work, causes data loss and/or has no workaround labels Apr 12, 2019
@shirishag75

This comment has been minimized.

@turt2live turt2live added this to In Progress in Web App Team via automation Apr 12, 2019
@turt2live turt2live moved this from In Progress to Raging Inferno 🔥🔥🔥 in Web App Team Apr 12, 2019
@lampholder
Copy link
Member

Perhaps related to #9425

I've just run some tests with a new test account, so far I have been able to:

  • create encrypted rooms
  • create a backup
  • log out
  • log in
  • change password
  • restore from backup
  • create new encrypted rooms
  • log out
  • log in
  • restore backup
  • log out
  • log in
  • change password
  • restore backup

Which I think demonstrates that both reading from and writing to the backup is succeeding for small key sets on matrix.org.

@lampholder
Copy link
Member

I'll try the password-reset-by-email flow to see if that makes any difference.

@shirishag75 are you able to provide a more detailed description of what you attempted and what failure modes you experienced?

@lampholder
Copy link
Member

From Matthew:

what i roughly did last night was:

login and enable keybackup (existing backup) on new desktop account
login and enable keybackup on iOS
change password on web
see that everything is undecryptable on web, but the dialog says it's participating in key backup with a valid sig from mobile but an invalid sig from desktop
log out of web and log in again, enter passphrase; everything worked.

@shirishag75

This comment has been minimized.

@lampholder

This comment has been minimized.

@shirishag75

This comment has been minimized.

@akontsevich

This comment has been minimized.

@jryans
Copy link
Collaborator

jryans commented Apr 17, 2019

@shirishag75 @akontsevich Thanks for the feedback, and I am sorry you are having trouble with Riot. It sounds like your issues are not related to key backup specifically, so please file new issues so we can track them separately.

@akontsevich
Copy link

@jryans, thanks, created element-hq/element-meta#1420.

@lampholder lampholder added P2 and removed S-Critical Prevents work, causes data loss and/or has no workaround 🔥 Fire 🔥 labels Apr 23, 2019
@lampholder
Copy link
Member

Deprioritising this some because we've had no other reports of it - if people do experience this please add to this issue/upvote

@jryans jryans removed this from Raging Inferno 🔥🔥🔥 in Web App Team Apr 24, 2019
@aaronraimist
Copy link
Collaborator

@ara4n can you still reproduce this? @turt2live, @Biep and I can't reproduce this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

9 participants