programming.dev
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
ForgottenFlux@lemmy.world to Privacy@lemmy.mlEnglish · 11 months ago

Signal under fire for storing encryption keys in plaintext on desktop app

stackdiary.com

external-link
message-square
253
link
fedilink
  • cross-posted to:
  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]
484
external-link

Signal under fire for storing encryption keys in plaintext on desktop app

stackdiary.com

ForgottenFlux@lemmy.world to Privacy@lemmy.mlEnglish · 11 months ago
message-square
253
link
fedilink
  • cross-posted to:
  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]
Signal under fire for storing encryption keys in plaintext
stackdiary.com
external-link
Popular encrypted messaging app Signal is facing criticism over a security issue in its desktop application. Researchers and app users are raising
  • refalo
    link
    fedilink
    arrow-up
    10
    arrow-down
    3
    ·
    edit-2
    11 months ago

    98% of desktop apps (at least on Windows and Linux) are already broken by design anyways. Any one app can spy on and keylog all other apps, all your home folder data, everything. And anyone can write a desktop app, so only using solutions that (currently) don’t have a desktop app version, seems silly to me.

    • explore_broaden@midwest.social
      link
      fedilink
      arrow-up
      5
      ·
      11 months ago

      I don’t think apps can read keystrokes for other apps on Wayland.

      • refalo
        link
        fedilink
        arrow-up
        2
        ·
        edit-2
        11 months ago

        Wayland doesn’t magically make other kinds of keyloggers stop working altogether though.

        https://old.reddit.com/r/linux/comments/23mj49/wayland_is_not_immune_to_keyloggers/

        https://github.com/Aishou/wayland-keylogger

        https://github.com/schauveau/sway-keylogger

        https://old.reddit.com/r/kde/comments/11h5tvl/wayland_security_keyloggers_are_back/

      • Possibly linux@lemmy.zip
        link
        fedilink
        English
        arrow-up
        2
        ·
        11 months ago

        Unless you have root

        • explore_broaden@midwest.social
          link
          fedilink
          arrow-up
          2
          ·
          11 months ago

          If you have root you could just update the kernel to one that lets you do whatever you want on the system, so there’s no way to stop the attacker from viewing the passwords if the app is capable of displaying them.

    • AProfessional@lemmy.world
      link
      fedilink
      English
      arrow-up
      7
      arrow-down
      2
      ·
      11 months ago

      Linux has a sandbox solution growing in popularity, flatpak.

      • Possibly linux@lemmy.zip
        link
        fedilink
        English
        arrow-up
        4
        ·
        11 months ago

        And Wayland. Xorg is a complete and utter mess

Privacy@lemmy.ml

privacy@lemmy.ml

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
  • Don’t promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

  • Lemmy.ml libre_culture
  • Lemmy.ml privatelife
  • Lemmy.ml DeGoogle
  • Lemmy.ca privacy

much thanks to @gary_host_laptop for the logo design :)

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 502 users / day
  • 2.48K users / week
  • 5.64K users / month
  • 15.9K users / 6 months
  • 549 local subscribers
  • 38.9K subscribers
  • 3.76K Posts
  • 97.2K Comments
  • Modlog
  • mods:
  • k_o_t@lemmy.ml
  • tmpod@lemmy.pt
  • Yayannick@lemmy.ml
  • ranok@sopuli.xyz
  • BE: 0.19.11
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org