ietf-wg-mimi / mimi-arch

An architecture for More Instant Messaging Interoperability
Other
4 stars 5 forks source link

e2e security state cannot be not "room state" #3

Closed rohan-wire closed 1 year ago

rohan-wire commented 1 year ago

These statements are contradictory (my emphasis):

"At any given time, all of the clients and servers participating in the room have the same view of the room's state."

"The state of the room includes a few types of information, most importantly:

"Messages sent within a room are protected by an end-to-end security protocol to ensure that the servers handling messages cannot inspect or tamper with messages."

bifurcation commented 1 year ago

Note that there is a clarification elsewhere that the servers know the public aspects of the E2E state (i.e., the ratchet tree).