Signal under fire for storing encryption keys in plaintext
stackdiary.com
external-link
Popular encrypted messaging app Signal is facing criticism over a security issue in its desktop application. Researchers and app users are raising
@Zak@lemmy.world
link
fedilink
English
773M

Signal should change this, but it’s typical of the traditional desktop OS security model in which applications running under the user’s account are considered trustworthy. Security-oriented software like Signal should take a more hardened approach, but this is not some glaring security hole.

I mean if somebody has physical access and is logged in they have your data anyways right?

@MeanEYE@lemmy.world
link
fedilink
English
2
edit-2
3M

deleted by creator

@MeanEYE@lemmy.world
link
fedilink
English
6
edit-2
3M

removed by mod

@cley_faye@lemmy.world
link
fedilink
English
53M

as Electron has no integration with the rest of the system,

You pretty much can use Electron to build an application and use native OS-specific features. It only requires thinking about it and a bit of work, but technically isn’t much harder to do than with anything else. And there are some things useful in windows for that, based on user login credentials.

But ultimately, if the developers didn’t care about doing that, it won’t happen, regardless of them using Electron or writing fully native apps.

Ghostalmedia
link
fedilink
English
173M

Storing stuff as plain text is so hot right now.

@N00dle@lemmy.world
link
fedilink
English
73M

Am I missing something? Hasn’t this been known for years now? I think they previously commented on this before.

@MeanEYE@lemmy.world
link
fedilink
English
4
edit-2
3M

deleted by creator

@thegreenguy@sopuli.xyz
link
fedilink
English
13M

According to the article there is a pull request which should fix it.

Flying Squid
link
fedilink
English
23M

I told the guy I buy a certain thing that should be legal in this state from that trusting Signal is a bad idea and he should use some coded language if we were going use it. I do anyway, but I doubt that matters.

@ForgottenFlux@lemmy.world
creator
link
fedilink
English
203M

deleted by creator

A pull request was made in April 2023 to implement Electron’s safeStorage API to address this problem, but there has been no follow-up from Signal

I hate hearing shit like this. What are they thinking?

@MeanEYE@lemmy.world
link
fedilink
English
4
edit-2
3M

deleted by creator

@ilickfrogs@lemmy.world
link
fedilink
English
11
edit-2
3M

Researchers were able to clone a user’s entire Signal session by copying the local storage directory, allowing them to access the chat history on a separate device

This has actually been useful for me in the past when reinstalling my OS lmao. In an ideal world we could reverify by entering a code from our phones to unlock the desktop local storage after moving it. My biggest wish for Signal is more seamless message history movement across devices and ecosystems. Fuck even proper back ups would be nice.

Create a post

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


  • 1 user online
  • 210 users / day
  • 601 users / week
  • 1.38K users / month
  • 4.49K users / 6 months
  • 1 subscriber
  • 7.41K Posts
  • 84.7K Comments
  • Modlog