Hacker News new | past | comments | ask | show | jobs | submit login

Belt and suspenders. It should be possible to kick a device, and be a timeout.



It is already possible to kick a device (go to Settings: Security in Element, for instance).

I've filed an issue at https://github.com/matrix-org/synapse/issues/10813 for inactivity timer logouts.

However, my point still stands that fallback keys are a good idea - you should kick the device out deliberately (manually or with a timer) rather than rely on a protocol quirk meaning that E2EE randomly breaks after some period of inactivity(!)


As long as the timer is passive (key expires) rather than active (key expunged).




Consider applying for YC's W25 batch! Applications are open till Nov 12.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: