Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

remove email-address unconditionally from title #2447

Merged
merged 2 commits into from
Dec 18, 2024

Conversation

r10s
Copy link
Member

@r10s r10s commented Dec 18, 2024

this was discussed in-person with various ppl on the last physical gathering :)

the email-address was removed for guaranteed-e2ee chats quite a while ago (deltachat/deltachat-android#2916) reason was, among others, that these addresses are often chatmail and therefore random. (despite expecting otherwise, that was fine for most users).

this PR removes the email-adress unconditionally:

  • having the email-address sometimes shown and sometimes not is confusing, and easily looks like a bug. this has become worse with the added vcard-support (before, there were rare non-guaranteed chats in chatmail) - resulting in more random addresses being shown

  • always protect against over-the-shoulder attacks

  • better privacy in screenshots sent around without thinking much before (cmp. Better privacy in screenshots #2329)

  • wrt impersonation attacks: the pure email address in the subtitle did never protect against impersonation, one could always get sth. trustworthy looking there, it is better to check the profile with additional information (eg. other chats) if in doubt

  • general cleaner, uncluttered layout

  • pave the way of the upcoming multi-addresses

drawback is that sometimes one more tap is needed to access the email-address - however, as it is always one tap away now, this can also go easily to the finger memory.

counterpart of deltachat/deltachat-android#3507

the email-address was removed for guaranteed-e2ee chats quite a while ago
(deltachat/deltachat-android#2916)
reason was, among others, that these addresses are often chatmail and therefore random.
(despite expecting otherwise, that was fine for most users).

this PR removes the email-adress unconditionally:

- having the email-address sometimes shown and sometimes not is confusing,
  and easily looks like a bug.
  this has become worse with the added vcard-support
  (before, there were rare non-guaranteed chats in chatmail) -
  resulting in more random addresses being shown

- _always_ protect against over-the-shoulder attacks

- better privacy in screenshots sent around without thinking much before
  (cmp. #2329)

- wrt impersonation attacks:
  the pure email address in the subtitle did never protect against impersonation,
  one could always get sth. trustworthy looking there,
  it is better to check the profile with additional information (eg. other chats) if in doubt

- general cleaner, uncluttered layout

- pave the way of the upcoming multi-addresses

drawback is that sometimes one more tap is needed to access the email-address -
however, as it is _always_ one tap away now,
this can also go easily to the finger memory.
@r10s r10s added the enhancement actually in development, user visible enhancement label Dec 18, 2024
@r10s r10s requested review from zeitschlag and Amzd December 18, 2024 16:53
Copy link
Collaborator

@zeitschlag zeitschlag left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM (except maybe a changelog-entry :P)

@r10s
Copy link
Member Author

r10s commented Dec 18, 2024

thanks for the reminder!

@r10s r10s merged commit 3da2897 into main Dec 18, 2024
1 check passed
@r10s r10s deleted the r10s/remove-addr-from-subtitle branch December 18, 2024 17:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement actually in development, user visible enhancement
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants