Skip to content

Abandoning an identity reset at the UIA step leaves broken account/device and later wipes the private cross-signing keys #3344

Description

@kaylendog

This is a meta issue for the two issues I found while investigating rage shakes earlier this week, present in both the Rust SDK and the JS SDK, and hence affects all of our software.

Recovery::reset_identity (Rust SDK) and RustCrypto.resetEncryption run their destructive steps against the local store (delete backup, disable secret storage, and generate a new private cross-signing identity) before UIA-gated fallible upload step. If the user never completes this, the server keeps the old identity while the local store holds a new one.

The next /keys/query response that includes our own user then removes every local private cross-signing key via PrivateCrossSigningIdentity::clear_if_differs (Rust SDK) while the device remains cross-signed by the old identity. This is particularly bad on EX platforms, since if the device was verified, the Rust SDK continues to report VerificationState::Verified since verification is performed using the public half of the old self-signing key, which the broken client still holds.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions