Skip to content

Secure-Join protocol may have bugs / produce inconsistencies #1177

@flub

Description

@flub
  • Bob verifies Alice even if Alice's vg-member-added or vc-contact-confirm message was not signed/encrypted
  • QR-joining a non-verified group relies on this bug. The current flow of messages does not allow for Bob to verify Alice in this case, but the implementation verifies Alice.

So question is how should we fix this? The protocol for QR-joining non-verified groups needs to change, but which way?

  • Do we want to keep the property that QR-joining a non-verified group verifies the inviter & invitee?
  • If not can we come up with a much shorter group-join option?

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions