• diaphragmwp@discuss.tchncs.de
    link
    fedilink
    English
    arrow-up
    2
    arrow-down
    1
    ·
    edit-2
    11 hours ago

    if you mean the “verify your new device” dialog

    That series of dialogs and pretty much everything else, including “verified devices” menu. Also, apart from race conditions it’s often just desync. Like, right now for me, nheko and Element say everything is unverified but fluffychat says everything including itself is verified.

    Not Element Classic, I meant aTox (Tox for Android). It still functions, though.

    • WhyJiffie@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      1
      ·
      4 hours ago

      Like, right now for me, nheko and Element say everything is unverified but fluffychat says everything including itself is verified.

      its not desynced, it is just not presented well. I think when it shows whether another device was verified, it actually does not show if you have completed verification of that device on your account, but instead whether that device is trusted by the current one (for purposes of sharing keys and whatever). in short, it’s not “the user account trusts the device”, but “this device trusts that device”.

      when you verify device A with device B, they will mutually trust each other. if device B already trusted devices C and D, device A will immediately start trusting them too.
      if you then log in on device E and you don’t verify it with any of the others, it will basically form a distinct “trust group”.

      in your case it seems there are also cases when device A says it trusts B, but B says it does not trust A. how long ago did you verify your nheko, element and fluffychat devices? it looks like their verification could not complete, maybe one of them had a bug at the time or crashed before properly saving its database.

      both issues won’t solve themselves automatically, you will have to verify the unverified device again. or if it does not work, report the problem with logs with the function in the app, on both sides.

      Not Element Classic, I meant aTox (Tox for Android). It still functicryptosystem

      I see. tox seems to be faring worse in security. in matrix, encryption is optional in the protocol, but it’s built on well studied cryptosystem. so far when it fails, it’s people not being able to read messages they should, not unexpected people being able to read messages. and that’s because of flaws in key distribution.

      in tox, it seems encryption is mandatory, but they roll their own cryptosystem. and their cryptosystem has flaws that nonexperts commonly run into

      Jason Donenfeld, wireguard creator to expert:

      I think when your homebrewed crypto protocol falls to basic crypto 101 vulnerabilities that modern AKEs are explicitly designed to prevent, it’s time to pin up the red banners telling people not to use your stuff.

      https://github.com/TokTok/c-toxcore/issues/426

      downvote was not me.

      • diaphragmwp@discuss.tchncs.de
        link
        fedilink
        English
        arrow-up
        1
        ·
        3 hours ago

        {verification}

        Ah, verification and trust are separate. Cool.

        Well, it was like 2 years ago? I had a different Element session than now (new one now for testing), nheko and fluffychat, and I pressed every possible button and nothing happened. When I open nheko, a dialog box says “Activate encryption”; “to make this device trusted {blah blah blah}” with a big “Verify” button. Pressing it does the same as closing the dialog, so a whole lot of nothing. Same right now. I did try logging out and back in on different devices, back then only though.

        in tox, it seems encryption is mandatory

        Because that’s how it’s routed, yes. Peer to peer with fewer points of centralization (still there for node discovery and TCP<>UDP tunnels and shit). The message encryption and the transport encryption are the same.

        https://github.com/TokTok/c-toxcore/issues/426
        Let’s say that Mallory, M, has stolen A’s private key

        I stopped reading there. I mean, good thing to know that it’s possible (especially for potential punks using it and whatnot), but I feel like opsec is fucked regardless in this case.