You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Two users called Alice join a room with the same avatar; a benign one and and a malicious one
The only way to spot messages from the malicious one is to tap on their avatar and read their mxid in the membership list.
Instead, when two users have the same (homomorphic) displayname, they should be disambiguated from each other by appending the mxid (in a different text format) so you can spot impersonation attacks.
Outcome
What did you expect?
disambiguated displaynames
What happened instead?
no disambiguation; security flaw
Your phone model
No response
Operating system version
No response
Application version
396
Homeserver
No response
Will you send logs?
Yes
The text was updated successfully, but these errors were encountered:
Applied to:
- timeline message
- detail of timeline message
- reply preview of timeline message
- rendering of state Event
Not applied to:
- room last message
- room member list (we display the MatrixId here)
- room member detail page
From element-x-ios created by ara4n: element-hq/element-x-ios#1845
Steps to reproduce
Outcome
What did you expect?
disambiguated displaynames
What happened instead?
no disambiguation; security flaw
Your phone model
No response
Operating system version
No response
Application version
396
Homeserver
No response
Will you send logs?
Yes
The text was updated successfully, but these errors were encountered: