"Manually verify all remote sessions" does nothing #27613
Labels
A-Element-R
Issues affecting the port of Element's crypto layer to Rust
A-Session-Mgmt
Session / device names, management UI, etc.
O-Occasional
Affects or can be seen by some users regularly or most users rarely
S-Major
Severely degrades major functionality or product features, with no satisfactory workaround
T-Defect
X-Regression
At the bottom of the Security & Privacy settings page, there is this switch:
As far as I can tell, it does absolutely nothing. In particular, when enabled at the same time as "Never send encrypted messages to unverified sessions from this session", encrypted messages are still sent to devices which are only verified via cross-signing.
I think we never wired up this switch as part of Element-R. IMHO, we should remove it.
The text was updated successfully, but these errors were encountered: