Voluntarily sharing informative posts from unaffiliated sources.
- 59 Posts
- 4 Comments
Joined 1 year ago
Cake day: January 16th, 2024
You are not logged in. If you use a Fediverse account that is able to follow users, you can follow this user.
deleted by creator
deleted by creator
ForgottenFlux@lemmy.worldOPto Privacy@lemmy.ml•Signal under fire for storing encryption keys in plaintext on desktop appEnglish1065·11 months agoSummary:
- Signal’s desktop app stores encryption keys for chat history in plaintext, making them accessible to any process on the system
- Researchers were able to clone a user’s entire Signal session by copying the local storage directory, allowing them to access the chat history on a separate device
- This issue was previously highlighted in 2018, but Signal has not addressed it, stating that at-rest encryption is not something the desktop app currently provides
- Some argue this is not a major issue for the “average user”, as other apps also have similar security shortcomings, and users concerned about security should take more extreme measures
- However, others believe this is a significant security flaw that undermines Signal’s core promise of end-to-end encryption
- A pull request was made in April 2023 to implement Electron’s safeStorage API to address this problem, but there has been no follow-up from Signal
deleted by creator
deleted by creator
deleted by creator
deleted by creator
deleted by creator
deleted by creator
deleted by creator
deleted by creator
deleted by creator
deleted by creator
deleted by creator
deleted by creator
deleted by creator
deleted by creator
deleted by creator
deleted by creator