omemo / gajim-omemo

Gajim plugin for OMEMO Multi-End Message and Object Encryption
86 stars 7 forks source link

Impossible to distinguish whether a message comes from a trusted source #154

Closed dnut closed 6 years ago

dnut commented 6 years ago

When a message comes in unencrypted, a very obvious warning is given:

Received plaintext message! Your next message will still be encrypted! Brent‎: **Unencrypted** lol

But when an encrypted messages comes from an untrusted source, it looks just like any other message. This is a major security weakness because any message could be coming from an untrusted source and you would never know. It is just as important to warn the user in this case as in the case of an unencrypted message. There should be similar warnings for untrusted messages:

Received encryped message from an untrusted source! Your messages cannot be decrypted by this recipient! Brent‎: **Untrusted** lol

lovetox commented 6 years ago

In a current Gajim version this is not the case anymore.

Please use the Gajim issue tracker in the future, https://dev.gajim.org/gajim/gajim-plugins/issues