Element-web: Option to only send encrypted messages to verified devices

Created on 20 Sep 2016  路  5Comments  路  Source: vector-im/element-web

Probably at the per-room level. Shared across all users, or per-user?

feature p1 major e2e

Most helpful comment

Just to confirm: this is very much on our radar, but we're also having to juggle all other issues coughed up by the beta - i.e. the Unknown Inbound Session ID bugs, verifying devices, and giving folks the ability to backup & restore E2E state. It will be coming RSN, and yes, it does pose a serious issue (as do the others).

All 5 comments

We've just discussed this very issue.

It worries me that an unverified party can silently intercept encrypted messages undetected.

And this is not a bug unique to vector-web

I would suggest having this per-user. Primarily because it empowers the user to increase security for their own messages without having to have the necessary room privileges.

Would be nice if this were supported for the entire room as well, but that's a Matrix spec issue too.

Just to confirm: this is very much on our radar, but we're also having to juggle all other issues coughed up by the beta - i.e. the Unknown Inbound Session ID bugs, verifying devices, and giving folks the ability to backup & restore E2E state. It will be coming RSN, and yes, it does pose a serious issue (as do the others).

i did this.

Was this page helpful?
0 / 5 - 0 ratings