I have a question for the #DeltaChat crowd: What if someone has a quick access to one of my devices, let's say I forget to lock my phone or laptop and an attacker adds their phone as a secondary device to my profile. Is there any mitigation possible? Could I realize it? Could I disable their access?

Cc @delta @ArcaneChat

Simplest idea I would have for that would be to switch off multi-device mode, change the password and add trusted devices again

But if they had access to your device, why would they spend time on only Delta, instead of just installing a rootkit? My point being, it’s often said that if an attacker had physical access, the game is already lost

@INeedMana yeah I know it's a serious security breach but I'm not thinking about big time attacker but someone like a partner in a toxic or abusive relationship, or a treasonous friend.

Someone who you unknowingly trust but has not really the means to install a rootkit. Just open Delta chat, flash the QR code and put the phone back down.

Someone doing that with Signal/Molly or would eventually get caught or at least blocked next time I review my devices list. But that can't happen with deltachat ?

I’ve only found this
Is there a way to limit and control the number of devices added via "Add Second Device"?

Hello, could you please advise: Is there a way to limit and control the number of devices added via “Add Second Device”?

Delta Chat
@lou_de_sel it is required to enter the iphone’s passcode to access the qr code in the iOS app (i’m assuming the android app is similar). if the abusive partner in question knows the passcode - they can do it, but you’ll get a notification about adding a secondary device anyway.
@ineedmana

Your account is on the devices, not on the server. You can't change your password (unless you're using non-chatmail servers)
@lou_de_sel

@lou_de_sel @delta @ArcaneChat Good question! If you use a vpn which doesn't allow LAN connections you could at least make it harder for them to add their device as second device.

Difficult to realize they have done this unless they start writing messages on your behalf and you can tell something was written that wasn't you.

hi, with the laptop it is easier to exploit, but in the case of phones it is not so easy: the pin/lock is asked when someone tries to add a second device or create a backup so they can’t just snap your profile there

besides that, to completely block access to certain apps, not only ArcaneChat/DeltaChat, android has a feature called “Private space” where you can protect with your lock/pin apps from being opened or even visible at all

in case it was in a laptop where it is much easier to steal since even if you could show an unavoidable warning about the profile transfer as discussed at support.delta.chat/t/…/4693 also the program data folder could be just copied, this is a problem of the low security of desktop systems, better never let anyone use your laptop in the same session as your personal session, you could have a guess session/user for such situations

if the worse happened and you suspect someone took your profile (which you would notice because some messages you didn’t read are not notified and appear as already read), there is no safe way out of it, since your identity lives in your pockets in your devices (the encryption identity) and not in a server, if someone gets it the only safe way out is to create a new profile and tell everyone to block the older contact and remove the old contact from all groups etc

Don't allow to delete "Device Messages" chat and some of its messages

your private key is your identity in Delta Chat, once someone gets your key, your profile is done for, they will be forever able to decrypt, spy and impersonate you, hence it is very important that if at any time “add second device” or manual backup option is used, a device message is added and it is not possible to delete it at least for X days. It must also be added the other way around: if you import a backup, so it is clear this is not a fresh account but a restored backup or second device a...

Delta Chat

@lou_de_sel highlight from previous answer about how to notice if someone took your profile (mainly if it is a non-professional spy but just some toxic partner):

you would notice because some messages you didn’t read are not notified and appear as already read

@lou_de_sel @delta @ArcaneChat
В #arcanechat не знайшов налаштувань безпеки де можна було б ввести умовний pin для блокування/розблокування самого застосунку.