Resetting Secure Backup ruins device verification / cross-signing #22168
Labels
A-E2EE
A-E2EE-Cross-Signing
A-E2EE-Key-Backup
O-Uncommon
Most users are unlikely to come across this or unexpected workflow
S-Major
Severely degrades major functionality or product features, with no satisfactory workaround
T-Defect
Steps to reproduce
Outcome
What did you expect?
Only the backup for message encryption keys should be rebuilt from scratch, which is a fairly invisible event.
What happened instead?
All of my clients appeared as untrusted devices to each other, anyone I had verified before became marked as unverified, and I appeared as unverified to them. It is as if cross-signing keys were reset.
And FWIW, Element Android said that it didn't have cross-signing private keys, as also seen here: element-hq/element-android#5090 (comment) . Logging out & back in fixed that issue, but the issue of lost verification remained.
This happened with both a matrix.org account & a self-hosted account.
Operating system
Fedora Workstation 36
Browser information
Firefox 100.0
URL for webapp
app.element.io & self-hosted Element Web v1.10.12
Application version
No response
Homeserver
matrix.org & self-hosted Synapse 1.57.1
Will you send logs?
No
The text was updated successfully, but these errors were encountered: