[Feature]: make self-destruction PIN less noticeable to an adversary
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 5/5
- Tiempo estimado
- Más de una semana
- Aptitud para principiantes
- 35/100
Línea de trabajo
The issue names no files, tests, or entry points. Start by comparing the regular and self-destruction PIN flows using the linked video, then review issue #4765 for the proposed decoy-account direction; done should make the two PIN outcomes indistinguishable to an adversary without breaking data destruction.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Is there an existing issue for this?
- I have searched the existing issues
Platform
Android
App version
6.5.6
Feature
The data destruction password works correctly, but an adversary can see with the naked eye whether the user entered the regular password or the self-destruction password. In some cases, the user may be put in danger if the adversary notices that they are hiding something. The video below compares the app’s behavior when the user enters the correct password and when they enter the self-destruction password:
https://youtube.com/shorts/AH-mBpOPC6U?si=FM9eO1UX1f8arBeh
First, the application loads instantly when the regular PIN is entered, but it takes several seconds to load when the user enters the duress PIN. A possible solution would be to add a delay to regular PIN verification, for example by using a key derivation function, so that entering the PIN takes roughly the same amount of time in both scenarios.
Second, when the regular PIN is entered, the size of the user data remains the same before and after unlocking the app. However, when the decoy PIN is entered, the size of the user data decreases after the app is unlocked. Moreover, if the user previously had several megabytes of user data and then shows the adversary an empty account, this may be enough for the adversary to conclude that the user has destroyed their data.
This issue is harder to solve. One possible mitigation would be to preallocate some space even for empty accounts, or to show a decoy user account instead of an empty one after the self-destruction password is entered, as proposed here.
- Lenguaje dominante
- Haskell
- Estrellas
- 19.5k
- Forks
- 1.4k
- Merge medio
- 1 d 21 h
- PR fusionados (30 d)
- 93
Preparar el entorno
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de simplex-chat/simplex-chat
-
enhancement triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
simplex-chat/simplex-chat#7585 ·
Los mantenedores suelen responder en 1 día
-
extremely outdated documentationAbierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
simplex-chat/simplex-chat#7248 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 75/100
simplex-chat/simplex-chat#6782 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 74/100
simplex-chat/simplex-chat#6772 ·
Los mantenedores suelen responder en 1 día
-
[Bug]:Abiertobug terminal triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
simplex-chat/simplex-chat#6752 ·
Los mantenedores suelen responder en 1 día
Todos los issues de simplex-chat/simplex-chat
Issues similares
-
bug
Dificultad 1/5 Menos de una hora Aptitud para principiantes 84/100
alunduil/network-arbitrary#180 ·
Los mantenedores suelen responder en 1 día
-
infrastructure
Dificultad 1/5 1-3 horas Aptitud para principiantes 65/100
alunduil/siren-json.hs#232 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
-
Test suite failure with 0.1.1Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
jgm/asciidoc-hs#14 ·
-
unfoldTree is too lazyAbiertomajor-release strictness Tree
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
haskell/containers#1260 ·
Los mantenedores suelen responder en 1 día