Skip to content

Abandoning an identity reset at the UIA step leaves broken account/device and later wipes the private cross-signing keys #5566

Description

@kaylendog

This is a sister issue to matrix-org/matrix-rust-sdk#7112, which in turn is a similar issue to matrix-org/matrix-rust-sdk#4728. Those issues deal with both the matrix-sdk and matrix-sdk-crypto components, but the same logical mishap occurs in the JS SDK too, which we can track here.


RustCrypto.resetEncryption runs its destructive steps against the local store (delete dehydrated devices and backups, disable secret storage, and generate a new private cross-signing identity) before UIA-gated fallible upload step. If the user never completes this, the server keeps the old identity while the local store holds a new one.

The next /keys/query response that includes our own user then removes every local private cross-signing key via PrivateCrossSigningIdentity::clear_if_differs in matrix-sdk-crypto (Rust SDK via WASM) while the device remains cross-signed by the old identity.

STR in Element Web

  1. Log in and set up recovery.
  2. Initiate an identity reset, then close when the password prompt appears. (aside: why can we cancel this?)
  3. Confirm that all private keys are still present via the dev tools.
  4. Log in a second device.
  5. Confirm that all private keys are no longer present via the dev tools.
  6. Observe that verifying the other device appears to work, but doesn't actually result in a verified device.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions