The trust-on-first-use policy leads to problems when receiving messages from two different devices of a contact before sending a message to them (as their IdentityKeys will not have been added yet). Since session trust will be managed externally anyway, this change is not a security problem, and will allow us to decrypt messages from yet-untrusted sessions. |
||
|---|---|---|
| .. | ||
| java/eu/siacs/conversations | ||
| res | ||
| AndroidManifest.xml | ||