pull down to refresh
412 sats \ 3 replies \ @ek 11 Jul 2024 freebie \ on: Signal downplays encryption key flaw, fixes it after X drama security
Encrypting the database key makes encryption at rest more secure but it doesn't prevent exfiltration in all scenarios afaik.
When you open Signal Desktop, your data gets decrypted and thus malware just has to wait until you do that.
I think that's what Whittaker means with "Signal cannot completely protect your data" and why this issue wasn't taken serious:
I can kind of get behind this reasoning but it's still weird that this wasn't implemented until now. It was maybe a UX vs security trade-off?
I co-sign this @ek
I do wonder if the recent spiciness around Signal and its board might be contributing to this stuff. It is hard to separate the technical from the political as we know from the bitcoin world.
reply
It's the same thing on the phone. If you caught Pegasus, then using Signal doesn't provide any extra privacy - all your taps or keystrokes can be tracked and exported.
reply
It also takes a while to open up. IDK if a fix would slow that down even more or not
reply