• eco_game@discuss.tchncs.de
    ·
    3 months ago

    I just read the full article, and I'm not even that concerned about storing the key in plaintext. I find the possibility of copying the files, and then being able to run the same session simultaneously a lot scarier.

  • Joël de Bruijn@lemmy.ml
    ·
    3 months ago

    While true I don't get why this is long known and also news at the same time.

    For Signal Backup tools for example this isn't a bug but a feature and the only way to make long term archival of chats possible.

  • JoeyJoeJoeJr@lemmy.ml
    ·
    3 months ago

    If your computer is compromised to the point someone can read the key, read words 2-5 again.

    This is FUD. Even if Signal encrypted the local data, at the point someone can run a process on your system, there's nothing to stop the attacker from adding a modified version of the Signal app, updating your path, shortcuts, etc to point to the malicious version, and waiting for you to supply the pin/password. They can siphon the data off then.

    Anyone with actual need for concern should probably only be using their phone anyway, because it cuts your attack surface by half (more than half if you have multiple computers), and you can expect to be in possession/control of your phone at all times, vs a computer that is often left unattended.