chatmosphere-app icon indicating copy to clipboard operation
chatmosphere-app copied to clipboard

Session is accessible from other clients - thus people could listen in

Open dkgrieshammer opened this issue 3 years ago • 0 comments

It's possible to access a Chatmosphere Session with normal Jitis Frontend and listen in to all conversations when Jitsi Frontend is installed on same Instance or when external access is enabled in Server Config (we're doing that for dev purposes, as well as official Jitsi.meet to be open for experimentation). If you don't want that, don't install Jitsi-Frontend on same Instance as Chatmosphere ;)

Todo

Make clear in Documentation how that is done

Original Issue from Samuel:

"Security issues with the related Jisti instance: if a user connects to the same room on the Jitsi server, he/she can see and hear everybody in the Chatmosphere discussion, but no one sees him/her from the Chatmosphere room. It allows spying on a conversation without being seen 😱"

dkgrieshammer avatar Apr 13 '21 14:04 dkgrieshammer