Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Status message spoofs contact verification #5847

Closed
3 tasks done
ethrgeist opened this issue Aug 7, 2024 · 1 comment
Closed
3 tasks done

Status message spoofs contact verification #5847

ethrgeist opened this issue Aug 7, 2024 · 1 comment

Comments

@ethrgeist
Copy link

ethrgeist commented Aug 7, 2024

  • I have searched open and closed issues for duplicates
  • I am submitting a bug report for existing functionality that does not work as intended
  • This isn't a feature request or a discussion topic

Bug description

At multiple places in the UI a personal status set to ✓ Verified looks near identical the contact verified mark.

HTML Char ✓ // Source

Steps to reproduce

  • Set the status on iOS to ✓ Verified
  • Look at places where the status is displayed

grafik

Actual result:

It looks a lot like people have verified my contact on their end, while they have not, this might help imposters or scammers to look trustworthy.

Expected result:

There is a clear distinction between the verified mark from the chat client and user controlled input from contacts.

In a group members list the verified mark even replaces the status in the same line if contact is verified with no notice or anything that could help to spot this simple manipulation.

This security feature should not be so easy to spoof.

Screenshots

For reference, a verified friend of mine in a shared group looks like this.

grafik

After i set my status to ✓ Verified, from the perspective of another account, it looks like they verified my account, when in fact, it's just my status message.

grafik

This is what my profile looks like, if some set my account to verified, could you tell which ✓ Verified is the one from the client and which is from my status? I sure could not.

grafik

The details page makes a small difference between my status and the actual verified, but it's not great.

grafik

But it get's worse, when a contact looks at my profile, which has not been set to verified by them, now it looks like i am verified to them.

grafik

Details page is no help to figure this out..., the pen could mean anything here.

grafik

Device info

Device: iPhone 12 Pro

iOS version: 17.6.0

Signal version: 7.22 (246)

Link to debug log

No debug since this is UI only

@elaine-signal
Copy link
Contributor

Thanks for pointing this out! We've updated the verified icon to be unique. 474c8c2

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

No branches or pull requests

2 participants