Skip to content

GitLab

  • Projects
  • Groups
  • Snippets
  • Help
    • Loading...
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in
Trac
Trac
  • Project overview
    • Project overview
    • Details
    • Activity
  • Issues 246
    • Issues 246
    • List
    • Boards
    • Labels
    • Service Desk
    • Milestones
  • Operations
    • Operations
    • Metrics
    • Incidents
  • Analytics
    • Analytics
    • Value Stream
  • Wiki
    • Wiki
  • Members
    • Members
  • Collapse sidebar
  • Activity
  • Create a new issue
  • Issue Boards

GitLab is used only for code review, issue tracking and project management. Canonical locations for source code are still https://gitweb.torproject.org/ https://git.torproject.org/ and git-rw.torproject.org.

  • Legacy
  • TracTrac
  • Issues
  • #17833

Closed
Open
Opened Dec 12, 2015 by cypherpunks@cypherpunks

Two contacts dangerously merging as one

Received a message apparently coming from PERSON A. From the very first line it became obvious that I was not communicating with a PERSON A but with someone else, I then quit Tor Messenger at once. Past initial confusion I contacted PERSON A via alternative channel to confirm that they did not send this message.

When I started Tor Messenger again, a new conversation was initiated, apparently by PERSON A, but this time, after the message, Tor Messenger displayed the following (see screenshot wtf2.png): "

  • The current conversation is private bu PERSON B's identity has not been verified.
  • The conversation will continue with PERSON A, using XMPP
  • Private conversation with PERSON A started. However, their identity has not been verified. "

However, despite this, I was still talking with PERSON B. Please note that contact with PERSON B was already supposed to be (unverified) in my contact list at that time, but somehow has disappeared from it.

Confusing, isn't it? :)

I tried to understand a bit of what was happening, and as seen on screenshot "wtf5.png", upon hovering over PERSON A's account icon, 2 accounts are now listed: "(unverified) PERSON A" and "(verified) PERSON A".

Upon clicking "(unverified) PERSON A" it is now clear that I actually open a conversation with PERSON B, as, when i try to verify this person's identity, a popup mentions (see screenshot "wtf.png") "verify PERSON B", while staying empty of any interface elements to verify it...

It appears that PERSON A and PERSON B are somehow merged into PERSON A's conversation window.

This could lead to very dangerous confusion... I hope this helps to further identify the source of the bug.

To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information
Assignee
Assign to
None
Milestone
None
Assign milestone
Time tracking
None
Due date
None
Reference: legacy/trac#17833