-
-
Notifications
You must be signed in to change notification settings - Fork 2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Resetting cross-signing/SSSS doesn't reset SSSS password #13212
Comments
Flagging as blocker, we definitely want a reset button that works. |
More importantly, the old recovery passphrase and key are still valid after the resetting procedure! |
Updated the title & description to reflect this |
Looks like this regressed in matrix-org/matrix-js-sdk#1311 |
We re-used the old SSSS key even when resetting, meaning we prompted the user to create a new passphrase but then ignored it and kept using the old one. Fixes element-hq/element-web#13212
We re-used the old SSSS key even when resetting, meaning we prompted the user to create a new passphrase but then ignored it and kept using the old one. Fixes element-hq/element-web#13212
Is key reset expected to work on Riot Android 0.9.10 and RiotX 0.18.1? After resetting it's showing a different set of devices as verified on Riot Android and RiotX than riot-web. Can file bug/send rageshake if necessary. |
It asks for the SSSS password after prompting you for a new one, but then appears to store the new cross-signing secrets with the old SSSS key, so your password stays the same.
The text was updated successfully, but these errors were encountered: