Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Notify change of security context #2990

Open
1 task done
smss2022 opened this issue Nov 29, 2023 · 0 comments
Open
1 task done

Notify change of security context #2990

smss2022 opened this issue Nov 29, 2023 · 0 comments
Labels
enhancement New feature or request

Comments

@smss2022
Copy link

Is there an existing request for feature?

  • I have searched the existing issues

What feature would you like?

The fact that a new device can be linked, unbeknownst to the correspondent(s) has major security implications.

Example: Alice works for the TLA (Three-Lettered-Agency). Bob is a field agent. Alice is Bob's handler.

Bob's trust in Alice is context-dependent: while he is sure that, at work, Alice has been screened and has no means of recording his messages (photos, screenshots or otherwise), outside of TLA's premises all bets are off. If Alice is a mole for the Adversary, Alice could link a new device and gain access to all the previous information exchanged with Bob, with Bob being none the wiser, as there's no notification when a new device is linked and synchronized

Even if Bob tried to mitigate the risk by setting an expiration timer for his messages exchanged with Alice, trying to make sure the information vanishes before Alice leaves her office, due to the defect in the synchronization logic, no actual mitigation occurs.

Anything else?

No response

@smss2022 smss2022 added the enhancement New feature or request label Nov 29, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

1 participant