Signal under fire for storing encryption keys in plaintext

https://stackdiary.com/signal-under-fire-for-storing-encryption-keys-in-plaintext/

13 points · 3 comments · view on lemmy.world

3 Comments

OsrsNeedsF2P@lemmy.ml · 40 pts · 2y

At-rest encryption is not something that Signal Desktop is currently trying to provide or has ever claimed to provide. Full-disk encryption can be enabled at the OS level on most desktop platforms.

pearsaltchocolatebar@discuss.online · 40 pts · 2y

That's how encryption keys are typically stored.

If someone has enough access to your system that they can get to your stored encryption keys, you have much bigger problems.

where_am_i@sh.itjust.works · 5 pts · 2y

Next in the news: cloud infrastructure engineer had ssh keys in plain text on their MacBook exposing 99999 servers! Everything you ever stored on the internet is potentially compromised!