Element-web: [e2e] Web-of-trust type of verification process for verifying keys in a group.

Created on 5 May 2017  ·  3Comments  ·  Source: vector-im/element-web

Related to #3656 a more "web-of-trust" could be an option too : verify/trust all devices trusted by user X or by all existing users in the room with a display of number of users that trust a given key.

feature e2e

Most helpful comment

@TheLastProject Is there any other solution to scaling verification?

N^2 verifications makes any E2EE room with more than 5 members basically unusable. There any many circumstances when you wouldn't want everyone to verify everyone.

Web-of-trust is fairly reliable in workplace/small-community environments. It only makes sense that I would be able to trust my boss's verifications. He's running the room after all, it's his ass if the E2EE is voided by improper verification.

All 3 comments

I don't quite like this idea. It simplifies mapping out who someone interacts with by seeing if the keys are trusted. It'll leak private metadata for very little possible benefit (most people don't correctly trust keys in the first place, even more technical users, I have never been able to trust the web of trust for GPG keys either).

@TheLastProject Is there any other solution to scaling verification?

N^2 verifications makes any E2EE room with more than 5 members basically unusable. There any many circumstances when you wouldn't want everyone to verify everyone.

Web-of-trust is fairly reliable in workplace/small-community environments. It only makes sense that I would be able to trust my boss's verifications. He's running the room after all, it's his ass if the E2EE is voided by improper verification.

Was this page helpful?
0 / 5 - 0 ratings

Related issues

ara4n picture ara4n  ·  3Comments

bagage picture bagage  ·  3Comments

lukebarnard1 picture lukebarnard1  ·  3Comments

niedzielski picture niedzielski  ·  3Comments

anoadragon453 picture anoadragon453  ·  3Comments