Warn before signing out of the last device, and offer an encrypted key export #72

Open
opened 2026-10-06 21:27:16 +00:00 by robocub · 0 comments
Member

Goal: nobody signs out of their last working device and loses their encrypted history without being clearly warned first and offered a way to save their keys.

When to warn

On Sign out (and Remove account), check the account's other devices (GET /devices + cross-signing state):

  • Is there another device that is signed in, verified (cross-signed), and seen recently (e.g. last_seen_ts within the last 14 days)? If yes, sign out normally; that device still holds the keys.
  • If no, and/or key backup isn't set up or this device's keys aren't fully backed up: show the warning before anything is deleted.

The warning

Plain and blunt: "This is your last signed-in device. If you sign out without saving your keys, you will permanently lose access to your past encrypted messages. Nobody can recover them for you."
Then offer, in order:

  1. Check your recovery key: "I have my recovery key saved". Better: verify it by entering it, so a wrong or old key is caught before sign-out.
  2. Export your keys to an encrypted file: pick a password (typed twice, strength hint), and Vommet writes the standard Matrix encrypted key export (the same MEGOLM SESSION DATA format Element uses), so the file also imports into Element and other clients. Clear note: "Don't lose this password. Without it, the file is useless."
  3. Set up key backup now, if it isn't (links to the #71 flow).
  4. Sign out anyway, deliberately less prominent, and requires an extra confirmation (e.g. tick "I understand I'll lose my encrypted messages").

Encrypted file as an alternative everywhere

The same encrypted export is offered in the #71 onboarding (page 2) as an alternative to a password manager: "No password manager? Save an encrypted key file instead, and remember its password." Also offered under Settings › Security › Export keys (with import too; upstream #631 asks for manual key import/export).

Notes

  • Check the Matrix Dart SDK's support for key export/import (megolm session export). If missing, implement the documented format (AES-CTR + HMAC-SHA256, PBKDF2 key from the password) in Dart or rust_lib_commet. Interop with Element's import is the acceptance test.
  • A key export covers keys up to the moment of export; the recovery key + online backup is the long-term answer. The copy should say so without being confusing.
  • The device check is per account; with several accounts, warn only for the one being signed out.

Related: #71 (encryption onboarding), #32 (recovery key at sign-in). Upstream: #631 (manual key import/export, open, no PR as of 2026-10-06).

Goal: nobody signs out of their last working device and loses their encrypted history without being clearly warned first and offered a way to save their keys. ## When to warn On **Sign out** (and Remove account), check the account's other devices (`GET /devices` + cross-signing state): - Is there **another device that is signed in, verified (cross-signed), and seen recently** (e.g. `last_seen_ts` within the last 14 days)? If yes, sign out normally; that device still holds the keys. - If **no**, and/or **key backup isn't set up or this device's keys aren't fully backed up**: show the warning before anything is deleted. ## The warning Plain and blunt: *"This is your last signed-in device. If you sign out without saving your keys, you will permanently lose access to your past encrypted messages. Nobody can recover them for you."* Then offer, in order: 1. **Check your recovery key:** "I have my recovery key saved". Better: verify it by entering it, so a wrong or old key is caught *before* sign-out. 2. **Export your keys to an encrypted file:** pick a password (typed twice, strength hint), and Vommet writes the standard Matrix encrypted key export (the same `MEGOLM SESSION DATA` format Element uses), so the file also imports into Element and other clients. Clear note: *"Don't lose this password. Without it, the file is useless."* 3. **Set up key backup now**, if it isn't (links to the #71 flow). 4. **Sign out anyway**, deliberately less prominent, and requires an extra confirmation (e.g. tick "I understand I'll lose my encrypted messages"). ## Encrypted file as an alternative everywhere The same encrypted export is offered in the #71 onboarding (page 2) as an alternative to a password manager: *"No password manager? Save an encrypted key file instead, and remember its password."* Also offered under Settings › Security › Export keys (with import too; upstream #631 asks for manual key import/export). ## Notes - Check the Matrix Dart SDK's support for key export/import (megolm session export). If missing, implement the documented format (AES-CTR + HMAC-SHA256, PBKDF2 key from the password) in Dart or `rust_lib_commet`. Interop with Element's import is the acceptance test. - A key export covers keys up to the moment of export; the recovery key + online backup is the long-term answer. The copy should say so without being confusing. - The device check is per account; with several accounts, warn only for the one being signed out. Related: #71 (encryption onboarding), #32 (recovery key at sign-in). Upstream: #631 (manual key import/export, open, no PR as of 2026-10-06).
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
nether/vommet#72
No description provided.