This is a sister issue to matrix-org/matrix-rust-sdk#7112, which in turn is a similar issue to matrix-org/matrix-rust-sdk#4728. Those issues deal with both the matrix-sdk and matrix-sdk-crypto components, but the same logical mishap occurs in the JS SDK too, which we can track here.
RustCrypto.resetEncryption runs its destructive steps against the local store (delete dehydrated devices and backups, disable secret storage, and generate a new private cross-signing identity) before UIA-gated fallible upload step. If the user never completes this, the server keeps the old identity while the local store holds a new one.
The next /keys/query response that includes our own user then removes every local private cross-signing key via PrivateCrossSigningIdentity::clear_if_differs in matrix-sdk-crypto (Rust SDK via WASM) while the device remains cross-signed by the old identity.
STR in Element Web
- Log in and set up recovery.
- Initiate an identity reset, then close when the password prompt appears. (aside: why can we cancel this?)
- Confirm that all private keys are still present via the dev tools.
- Log in a second device.
- Confirm that all private keys are no longer present via the dev tools.
- Observe that verifying the other device appears to work, but doesn't actually result in a verified device.
This is a sister issue to matrix-org/matrix-rust-sdk#7112, which in turn is a similar issue to matrix-org/matrix-rust-sdk#4728. Those issues deal with both the
matrix-sdkandmatrix-sdk-cryptocomponents, but the same logical mishap occurs in the JS SDK too, which we can track here.RustCrypto.resetEncryptionruns its destructive steps against the local store (delete dehydrated devices and backups, disable secret storage, and generate a new private cross-signing identity) before UIA-gated fallible upload step. If the user never completes this, the server keeps the old identity while the local store holds a new one.The next
/keys/queryresponse that includes our own user then removes every local private cross-signing key viaPrivateCrossSigningIdentity::clear_if_differsinmatrix-sdk-crypto(Rust SDK via WASM) while the device remains cross-signed by the old identity.STR in Element Web