That post seems to be missing.
catalog3115 140 points 2 years ago

E2EE is not supposed to protect if device get compromised.

path: 0 11024581, hotness: undefined, score: 140, children: 43
NegativeLookBehind 62 points 2 years ago
path: 0 11024581 11025108, hotness: undefined, score: 62, children: 17
refalo -9 points 2 years ago

Source:

path: 0 11024581 11025108 11030492, hotness: undefined, score: -9, children: 16
Zpiritual 9 points 2 years ago

Microsoft are integrating adware and spyware straight into the os.

path: 0 11024581 11025108 11030492 11036709, hotness: undefined, score: 9, children: 5
refalo -1 points 2 years ago

Source:

path: 0 11024581 11025108 11030492 11036709 11057811, hotness: undefined, score: -1, children: 4
Vilian 4 points 2 years ago

source: 93% of ransomware are windows based

path: 0 11024581 11025108 11030492 11033002, hotness: undefined, score: 4, children: 8
WldFyre 11 points 2 years ago

99% of people in France are French

path: 0 11024581 11025108 11030492 11033002 11041810, hotness: undefined, score: 11, children: 4
refalo 5 points 2 years ago

Correlation is not causation.

path: 0 11024581 11025108 11030492 11033002 11033014, hotness: undefined, score: 5, children: 1
Pacmanlives 2 points 2 years ago
path: 0 11024581 11025108 11030492 11033002 11048598, hotness: undefined, score: 2, children: 0
it_depends_man 3 points 2 years ago

"The computer" decides when to install updates and which ones to install.

path: 0 11024581 11025108 11030492 11035234, hotness: undefined, score: 3, children: 0
potatopotato 18 points 2 years ago

Intrinsically/semantically no but the expectation is that the texts are encrypted at rest and the keys are password and/or tpm+biometric protected. That's just how this works at this point. Also that's the government standard for literally everything from handheld devices to satellites (yes, actually).

At this point one of the most likely threat vectors is someone just taking your shit. Things like border crossings, rubber stamped search warrants, cops raid your house because your roommate pissed them off, protests, needing to go home from work near a protest, on and on.

path: 0 11024581 11028406, hotness: undefined, score: 18, children: 18
9tr6gyp3 14 points 2 years ago

If your device is turned on and you are logged in, your data is no longer at rest.

Signal data will be encrypted if your disk is also encrypted.

If your device's storage is not encrypted, and you don't have any type of verified boot process, then thats on you, not Signal.

path: 0 11024581 11028406 11030302, hotness: undefined, score: 14, children: 16
douglasg14b 6 points 2 years ago

That's not how this works.

If the stored data from signal is encrypted and the keys are not protected than that is the security risk that can be mitigated using common tools that every operating system provides.

You're defending signal from a point of ignorance. This is a textbook risk just waiting for a series of latent failures to allow leaks or access to your "private" messages.

There are many ways attackers can dump files without actually having privileged access to write to or read from memory. However, that's a moot point as neither you nor I are capable of enumerating all potential attack vectors and risks. So instead of waiting for a known failure to happen because you are personally "confident" in your level of technological omnipotence, we should instead not be so blatantly arrogant and fill the hole waiting to be used.


Also this is a common problem with framework provided solutions:

https://www.electronjs.org/...

This is such a common problem that it has been abstracted into apis for most major desktop frameworks. And every major operating system provides a key ring like service for this purpose.

Because this is a common hole in your security model.

path: 0 11024581 11028406 11030302 11031066, hotness: undefined, score: 6, children: 3
9tr6gyp3 -2 points 2 years ago

Having Signal fill in gaps for what the OS should be protecting is just going to stretch Signal more than it already does. I would agree that if Signal can properly support that kind of protection on EVERY OS that its built for, go for it. But this should be an OS level protection that can be offered to Signal as an app, not the other way around.

path: 0 11024581 11028406 11030302 11031066 11032051, hotness: undefined, score: -2, children: 2
uis 1 point 2 years ago

Signal data will be encrypted if your disk is also encrypted.

True.

and you don't have any type of verified boot process

How motherboard refusing to boot from another drive would protect anything?

path: 0 11024581 11028406 11030302 11048696, hotness: undefined, score: 1, children: 11
9tr6gyp3 1 point 2 years ago

Its more about protecting your boot process from malware.

path: 0 11024581 11028406 11030302 11048696 11050957, hotness: undefined, score: 1, children: 10
Redjard 4 points 2 years ago

TPM isn't all that reliable. You will have people upgrading their pc, or windows update updating their bios, or any number of other reasons reset their tpm keys, and currently nothing will happen. In effect people would see Signal completely break and loose all their data, often seemingly for no reason.

Talking to windows or through it to the TPM also seems sketchy.

In the current state of Windows, the sensible choice is to leave hardware-based encryption to the OS in the form of disk encryption, unfortunate as it is. The great number of people who loose data or have to recover their backup disk encryption key from their Microsoft account tells how easily that system is disturbed (And that Microsoft has the decryption keys for your encrypted date).

path: 0 11024581 11028406 11030749, hotness: undefined, score: 4, children: 0
AlexWIWA 8 points 2 years ago

Mfw end to end can be compromised at the end.

That said, they should fix this anyway

path: 0 11024581 11032123, hotness: undefined, score: 8, children: 0
uis 3 points 2 years ago

Indeed, End-to-End Encryption protects data between those ends, not ends themselves. If ends are compromised, no math will help you.

path: 0 11024581 11048655, hotness: undefined, score: 3, children: 0
RealFknNito -4 points 2 years ago

Plaintext should never be used in any application that deals with security, ever.

path: 0 11024581 11031126, hotness: undefined, score: -4, children: 3
lemmyvore 7 points 2 years ago

Oh no, tell that to SSH.

path: 0 11024581 11031126 11034848, hotness: undefined, score: 7, children: 0
possiblylinux127 4 points 2 years ago

It doesn't use plain text. It is end to end encrypted but that isn't what this "issue" is

path: 0 11024581 11031126 11039311, hotness: undefined, score: 4, children: 0
eager_eagle 3 points 2 years ago

unless you're reading ciphertext yourself, this doesn't make sense

path: 0 11024581 11031126 11035766, hotness: undefined, score: 3, children: 0
ForgottenFlux 98 points 2 years ago
path: 0 11024137, hotness: undefined, score: 98, children: 14
GolfNovemberUniform 20 points 2 years ago

Oh wow that's quite a red flag ngl

path: 0 11024137 11024187, hotness: undefined, score: 20, children: 12
poVoq 35 points 2 years ago

If your system is compromised to such an extend, it really doesn't make much difference how the keys are stored at rest.

path: 0 11024137 11024187 11024265, hotness: undefined, score: 35, children: 10
phoneymouse 26 points 2 years ago
path: 0 11024137 11024187 11024265 11027986, hotness: undefined, score: 26, children: 3
nekusoul 7 points 2 years ago

All it takes is an App that you”trust” to break that trust

I get what you're trying to say, but that's something I'd classify as "compromised" as well.

path: 0 11024137 11024187 11024265 11027986 11030554, hotness: undefined, score: 7, children: 2
GolfNovemberUniform -12 points 2 years ago

But my system is not compromised?

path: 0 11024137 11024187 11024265 11024946, hotness: undefined, score: -12, children: 5
poVoq 9 points 2 years ago

Did you read the article?

path: 0 11024137 11024187 11024265 11024946 11025229, hotness: undefined, score: 9, children: 0
refalo 4 points 2 years ago

How do you know?

path: 0 11024137 11024187 11024265 11024946 11030614, hotness: undefined, score: 4, children: 3
possiblylinux127 0 points 2 years ago

Why? They would need access to the device

path: 0 11024137 11024187 11025984, hotness: undefined, score: 0, children: 0
refalo 2 points 2 years ago

Thanks ChatGPT.

path: 0 11024137 11030633, hotness: undefined, score: 2, children: 0
x1gma 83 points 2 years ago

How in the fuck are people actually defending signal for this, and with stupid arguments such as windows is compromised out of the box?

You. Don't. Store. Secrets. In. Plaintext.

There is no circumstance where an app should store its secrets in plaintext, and there is no secret which should be stored in plaintext. Especially since this is not some random dudes random project, but a messenger claiming to be secure.

Edit: "If you got malware then this is a problem anyway and not only for signal" - no, because if secure means to store secrets are used, than they are encrypted or not easily accessible to the malware, and require way more resources to obtain. In this case, someone would only need to start a process on your machine. No further exploits, no malicious signatures, no privilege escalations.

"you need device access to exploit this" - There is no exploiting, just reading a file.

path: 0 11029921, hotness: undefined, score: 83, children: 20
lemmyvore 43 points 2 years ago

You. Don't. Store. Secrets. In. Plaintext.

SSH stores the secret keys in plaintext too. In a home dir accessible only by the owning user.

I won't speak about Windows but on Linux and other Unix systems the presumption is that if your home dir is compromised you're fucked anyway. Effort should be spent on actually protecting access to the home personal files not on security theater.

path: 0 11029921 11035083, hotness: undefined, score: 43, children: 9
x1gma 10 points 2 years ago

Kinda expected the SSH key argument. The difference is the average user group.

The average dude with a SSH key that's used for more than their RPi knows a bit about security, encryption and opsec. They would have a passphrase and/or hardening mechanisms for their system and network in place. They know their risks and potential attack vectors.

The average dude who downloads a desktop app for a messenger that advertises to be secure and E2EE encrypted probably won't assume that any process might just wire tap their whole "encrypted" communications.

Let's not forget that the threat model has changed by a lot in the last years, and a lot of effort went into providing additional security measures and best practices. Using a secure credential store, additional encryption and not storing plaintext secrets are a few simple ones of those. And sure, on Linux the SSH key is still a plaintext file. But it's a deliberate decision of you to keep it as plaintext. You can at least encrypt with a passphrase. You can use the actual working file permission model of Linux and SSH will refuse to use your key with loose permissions. You would do the same on Windows and Mac and use a credential store and an agent to securely store and use your keys.

Just because your SSH key is a plaintext file and the presumption of a secure home dir, you still wouldn't do a ~/passwords.txt.

path: 0 11029921 11035083 11036033, hotness: undefined, score: 10, children: 0
floquant 8 points 2 years ago

Not true, SSH keys need their passphrase to be used. If you don't set one, that's on you.

path: 0 11029921 11035083 11035197, hotness: undefined, score: 8, children: 6
Mubelotix 17 points 2 years ago

Come on, 95% of users don't set passwords on their ssh keys

path: 0 11029921 11035083 11035197 11035727, hotness: undefined, score: 17, children: 3
idunnololz 5 points 2 years ago

Where are these stays from lmao.

path: 0 11029921 11035083 11035197 11035727 11040484, hotness: undefined, score: 5, children: 2
dave 10 points 2 years ago

Well yes, but also how would users react if they had to type in their passphrase every time they open the app? This is also exactly what we're giving up everywhere else by clicking 'remember this device'.

path: 0 11029921 11035083 11035197 11035603, hotness: undefined, score: 10, children: 0
lemmyvore 2 points 2 years ago

If someone gets access they can delete your keys, or set up something that can intercept your keys in other ways.

The security of data at rest is just one piece of the puzzle. In many systems the access to the data is considered much more important than whether the data itself is encrypted in one particular scenario.

path: 0 11029921 11035083 11035197 11035754, hotness: undefined, score: 2, children: 0
uis 0 points 2 years ago

SSH has encrypted keys

path: 0 11029921 11035083 11048494, hotness: undefined, score: 0, children: 0
possiblylinux127 16 points 2 years ago

If someone has access to your machine you are screwed anyway. You need to store the encryption key somewhere

path: 0 11029921 11039215, hotness: undefined, score: 16, children: 1
x1gma -1 points 2 years ago

Yes, in your head, and in your second factor, if possible, keeping derived secrets always encrypted at rest, decrypting at the latest possible moment and not storing (decrypted) secrets in-memory for longer than absolutely necessary at use.

path: 0 11029921 11039215 11039604, hotness: undefined, score: -1, children: 0
refalo 12 points 2 years ago

How in the fuck are people actually defending signal for this

Probably because Android (at least) already uses file-based encryption, and the files stored by apps are not readable by other apps anyways.

And if people had to type in a password every time they started the app, they just wouldn't use it.

path: 0 11029921 11030385, hotness: undefined, score: 12, children: 4
Liz 19 points 2 years ago

Popular encrypted messaging app Signal is facing criticism over a security issue in its desktop application.

Emphasis mine.

path: 0 11029921 11030385 11031646, hotness: undefined, score: 19, children: 2
ChapulinColorado 13 points 2 years ago

I think the point is the developers might have just migrated the code without adjustments since that is how it was implemented before. Similar to how PC game ports sometimes run like shit since they are a close 1-1 of the original which is not always the most optimized or ideal, but the quickest to output.

path: 0 11029921 11030385 11031646 11031711, hotness: undefined, score: 13, children: 1
x1gma 6 points 2 years ago

Been a few days since using electron, but AFAIK electron can't be used as a wrapper for android apps, or can it? Or is their android app a web app wrapped into a "native" android app too?

Also, since this seems to be an issue since 2018, 6 years should be plenty to rewrite using a native secure storage...

path: 0 11029921 11030385 11031646 11031711 11036472, hotness: undefined, score: 6, children: 0
uis 2 points 2 years ago

AFAIK Android encrypts entire fs with one key. And ACL is not encryption.

path: 0 11029921 11030385 11048560, hotness: undefined, score: 2, children: 0
uis 6 points 2 years ago

You. Don't. Store. Secrets. In. Plaintext.

Ok. Enter password at every launch.

path: 0 11029921 11048480, hotness: undefined, score: 6, children: 0
pedroapero 1 point 2 years ago

All your session cookies are stored in plaintext.

path: 0 11029921 11139592, hotness: undefined, score: 1, children: 1
x1gma 1 point 2 years ago

Chrome cookies are encrypted, for exactly the reasons stated. If malware gains access to your system and compromises it in a way that DPAPI calls can be replicated in the way Chrome does it, then your sessions will also be compromised. But this is way harder to do, and at least prevents trivial data exfiltration.

path: 0 11029921 11139592 11139739, hotness: undefined, score: 1, children: 0
Mubelotix 61 points 2 years ago

Sure, I was aware. You have the same problem with ssh keys, gpg keys and many other things

path: 0 11035715, hotness: undefined, score: 61, children: 5
mr_satan 11 points 2 years ago

However, you can save encrypted ssh, gpg keys and save that encryption key in the OS keyring.

path: 0 11035715 11036545, hotness: undefined, score: 11, children: 4
uis 3 points 2 years ago

Yes, but you STILL need to enter password on every reboot.

path: 0 11035715 11036545 11048455, hotness: undefined, score: 3, children: 0
derpgon 2 points 2 years ago

Is it possible to seamlessly integrate, so when something requests those keys you'll get a prompt?

path: 0 11035715 11036545 11036808, hotness: undefined, score: 2, children: 2
todd_bonzalez 10 points 2 years ago
path: 0 11035715 11036545 11036808 11037440, hotness: undefined, score: 10, children: 1
derpgon 3 points 2 years ago

Nice, didn't know, I'll look into it

path: 0 11035715 11036545 11036808 11037440 11037474, hotness: undefined, score: 3, children: 0
Carbophile 57 points 2 years ago

The backlash is extremely idiotic. The only two options are to store it in plaintext or to have the user enter the decryption key every time they open it. They opted for the more user-friendly option, and that is perfectly okay.

If you are worried about an outsider extracting it from your computer, then just use full disk encryption. If you are worried about malware, they can just keylog you when you enter the decryption key anyways.

path: 0 11040067, hotness: undefined, score: 57, children: 5
x1gma 14 points 2 years ago

The third option is to use the native secret vault. MacOS has its Keychain, Windows has DPAPI, Linux has has non-standardized options available depending on your distro and setup.

Full disk encryption does not help you against data exfil, it only helps if an attacker gains physical access to your drive without your decryption key (e.g. stolen device or attempt to access it without your presence).

Even assuming that your device is compromised by an attacker, using safer storage mechanisms at least gives you time to react to the attack.

path: 0 11040067 11042654, hotness: undefined, score: 14, children: 2
lengau 9 points 2 years ago

Linux has the secret service API that has been a freedesktop.org standard for 15 years.

path: 0 11040067 11042654 11048399, hotness: undefined, score: 9, children: 1
uis 2 points 2 years ago

Secret service API. Damn. That's how FSB knows what it knows.

path: 0 11040067 11042654 11048399 11048445, hotness: undefined, score: 2, children: 0
Zak 7 points 2 years ago

The alternative is safeStorage, which uses the operating system's credential management facility if available. On Mac OS and sometimes Linux, this means another process running in the user's account is prevented from accessing it. Windows doesn't have a protection against that, but all three systems do protect the credentials if someone copies data offline.

Signal should change this, but it isn't a major security flaw. If an attacker can copy your home directory or run arbitrary code on your device, you're already in big trouble.

path: 0 11040067 11041423, hotness: undefined, score: 7, children: 0
refalo 1 point 2 years ago

A better thing to be worried about IMO is that Signal contains proprietary code. Also to my knowledge nobody is publicly verifying the supposed "reproducible builds" if they even still exist.

path: 0 11040067 11068378, hotness: undefined, score: 1, children: 0
HappyTimeHarry 52 points 2 years ago

That applies to pretty much all desktop apps, your browser profile can be copied to get access to all your already logged in cookie sessions for example.

path: 0 11024964, hotness: undefined, score: 52, children: 6
kryllic 11 points 2 years ago

IIRC this is how those Elon musk crypto livestream hacks worked on YouTube back in the day, I think the bad actors got a hold of cached session tokens and gave themselves access to whatever account they were targeting. Linus Tech Tips had a good bit in a WAN show episode

path: 0 11024964 11026431, hotness: undefined, score: 11, children: 0
douglasg14b 4 points 2 years ago

And there are ways to mitigate this attack (essentially the same as a AiTM or pass-the-cookie attacks, so look those up). Thus rendering your argument invalid.

Just because "something else might be insecure", doesn't in any way imply "everything else should also be insecure as well".

path: 0 11024964 11031089, hotness: undefined, score: 4, children: 4
possiblylinux127 3 points 2 years ago

It is the same concept. Once your machine is pwded you are screwed

path: 0 11024964 11031089 11039296, hotness: undefined, score: 3, children: 3
douglasg14b 2 points 2 years ago

That's all hinges on the assumption that your computer is pwned. Which is wrong

You don't necessarily have to have privileged access to read files or exfiltrated information.

That point doesn't matter anyways though because you're completely ignoring the risk here. Please Google "Swiss cheese model". Your comment is a classic example of non-security thinking.... It's the same comment made 100x in this thread with different words

Unless you can list out all possible risks and exploits which may affect this issue, then you are not capable of making judgement calls on the risk itself.

path: 0 11024964 11031089 11039296 11040618, hotness: undefined, score: 2, children: 2
possiblylinux127 1 point 2 years ago

You act as though you somehow have more knowledge than everyone else. They problem is that you don't understand encryption and permissions. You can't just magically make something unreadable by programs with the same permission level. If you encrypt it there will need to be a key to decrypt it. That can could conceivably be encrypted with a password but that would require someone to enter a password. If they don't enter a password they key will be stored plain text so anyone could easily decrypt your messages. Programs running as a user have the same permissions as that user. Does that make sense? You can't just make something selectively unreadable with the current security model. I guess you could try to implement some sort or privileged daemon but that would open up more issues than it solved.

I would have a problem if Signal claimed that the desktop messages were encrypted at rest. However, they don't make any such claim. If you are concerned about security I would recommend running everything in virtual machines and flatpaks. This way the chances of something misbehaving in a way that causes harm is minimized.

path: 0 11024964 11031089 11039296 11040618 11042257, hotness: undefined, score: 1, children: 1
thayer 52 points 2 years ago

While it would certainly be nice to see this addressed, I don't recall Signal ever claiming their desktop app provided encryption at rest. I would also think that anyone worried about that level of privacy would be using disappearing messages and/or regularly wiping their history.

That said, this is just one of the many reasons why whole disk encryption should be the default for all mainstream operating systems today, and why per-app permissions and storage are increasingly important too.

path: 0 11024575, hotness: undefined, score: 52, children: 22
ooterness 29 points 2 years ago

Full disk encryption doesn't help with this threat model at all. A rogue program running on the same machine can still access all the files.

path: 0 11024575 11025615, hotness: undefined, score: 29, children: 1
thayer 18 points 2 years ago

It does help greatly in general though, because all of your data will be encrypted when the device is at rest. Theft and B&Es will no longer present a risk to your privacy.

Per-app permissions address this specific threat model directly. Containerized apps, such as those provided by Flatpak can ensure that apps remain sandboxed and unable to access data without explicit authorization.

path: 0 11024575 11025615 11026055, hotness: undefined, score: 18, children: 0
BearOfaTime 5 points 2 years ago

Exactly.

I'll admit to being lazy and not enabling encryption on my Windows laptops. But if I deployed something for someone, it would be encrypted.

path: 0 11024575 11024732, hotness: undefined, score: 5, children: 0
Zak 4 points 2 years ago

I don’t recall Signal ever claiming their desktop app provided encryption at rest.

I'm not sure if they've claimed that, but it does that using SQLCipher.

path: 0 11024575 11028917, hotness: undefined, score: 4, children: 0
Tywele 4 points 2 years ago

Does encrypting your disks change something for the end user in day to day usage? I'm honest, I've never used encrypted disks in my life.

path: 0 11024575 11025271, hotness: undefined, score: 4, children: 17
communism 11 points 2 years ago

Whole disk encryption wouldn't change your daily usage, no. It just means that when you boot your PC you have to enter your passphrase. And if your device becomes unbootable for whatever reason, and you want to access your drive, you'll just have to decrypt it first to be able to read it/write to it, e.g. if you want to rescue files from a bricked computer. But there's no reason not to encrypt your drive. I can't think of any downsides.

path: 0 11024575 11025271 11025369, hotness: undefined, score: 11, children: 2
lemmyvore 2 points 2 years ago

If any part of the data gets corrupted you lose the whole thing. Recovery tools can't work with partially corrupted encrypted data.

path: 0 11024575 11025271 11025369 11035122, hotness: undefined, score: 2, children: 1
communism 2 points 2 years ago

I don't think that's a big deal with Signal data. You can log back into your account, you'd just lose your messages. idk how most people use Signal but I have disappearing messages on for everything anyway, and if a message is that important to you then back it up.

path: 0 11024575 11025271 11025369 11035122 11037376, hotness: undefined, score: 2, children: 0
devfuuu 4 points 2 years ago

It's transparent for end user basically, but protects the laptop at least when outside and if someone steals the computer. As long as it was properly shutdown.

path: 0 11024575 11025271 11026002, hotness: undefined, score: 4, children: 4
ruse8145 -1 points 2 years ago

Define properly shut down. Do your thieves usually ask first?

path: 0 11024575 11025271 11026002 11029667, hotness: undefined, score: -1, children: 3
refalo 4 points 2 years ago

I think they're just referring to an outdated concept of OSes with non-journaling filesystems that can cause data corruption if the disk is shut off abruptly, which in theory could corrupt the entire disk at once if it was encrypted at a device level. But FDE was never used in the time of such filesystems anyways.

path: 0 11024575 11025271 11026002 11029667 11030570, hotness: undefined, score: 4, children: 0
devfuuu 0 points 2 years ago

If you suspend the laptop when moving locations instead of shutting down or hibernating to disk then disk encryption is useless.

path: 0 11024575 11025271 11026002 11029667 11030475, hotness: undefined, score: 0, children: 1
thayer 3 points 2 years ago

No, the average user will never know the difference. I couldn't tell you exactly what the current performance impact is for hardware encryption, but it's likely around 1-4% depending on the platform (I use LUKS under Linux).

For gamers, it's likely a 1-5 FPS loss, depending on your hardware, which is negligible in my experience. I play mostly first and third person shooter-style games at 1440p/120hz, targeting 60-90 FPS, and there's no noticeable impact (Ryzen 5600 / RX 6800XT).

path: 0 11024575 11025271 11026763, hotness: undefined, score: 3, children: 7
refalo 4 points 2 years ago

For gamers, it’s likely a 1-5 FPS loss

I highly doubt it... would love to see some hard data on that. Most algorithms used for disk encryption these days are already faster than RAM, and most games are not reading gigabytes/sec from the disk every frame during gameplay for this to ever matter.

path: 0 11024575 11025271 11026763 11030523, hotness: undefined, score: 4, children: 0
ruse8145 3 points 2 years ago

If it has to go to disk for immediate loading of assets while playing a video game you're losing more than 1-5 fps

path: 0 11024575 11025271 11026763 11029661, hotness: undefined, score: 3, children: 5
refalo 3 points 2 years ago

Maybe, but not every frame while you're playing. No game is loading gigs of data every frame. That would be the only way most encryption algorithms would slow you down.

path: 0 11024575 11025271 11026763 11029661 11030604, hotness: undefined, score: 3, children: 2
thayer 3 points 2 years ago

Yeah, I'm sure there are a lot of variables there. I can only say that in my experience, I noticed zero impact to gaming performance when I started encrypting everything about 10 years ago. No stuttering or noticeable frame loss. It was a seamless experience and brings real peace of mind knowing that our financial info, photos, and other sensitive files are safely locked away.

path: 0 11024575 11025271 11026763 11029661 11034167, hotness: undefined, score: 3, children: 1
refalo 3 points 2 years ago

It depends on how you set it up. I think the default in some cases (like Windows Bitlocker) is to store the key in TPM, so everything becomes transparent to the user at that point, although many disagree with this method for privacy/security reasons.

The other method is to provide a password or keyfile during bootup, which does change something for the end user somewhat.

path: 0 11024575 11025271 11030596, hotness: undefined, score: 3, children: 0
Prethoryn 31 points 2 years ago

Ah yes, another prime example that demonstrates that Lemmy is no different than Reddit. Everyone thinks they are a professional online.

Nothing sensitive should ever lack encryption especially in the hands of a third party company managing your data claiming you are safe and your privacy is protected.

No one is invincible and it's okay to criticize the apps we hold to high regards. If your are pissed people are shitting on Signal you should be pissed Signal gave people a reason to shit on them.

path: 0 11030526, hotness: undefined, score: 31, children: 8
possiblylinux127 14 points 2 years ago

Where are you going to store the encryption key? At the end of the day the local machine is effectively pwded anyway

path: 0 11030526 11039192, hotness: undefined, score: 14, children: 0
todd_bonzalez 4 points 2 years ago
path: 0 11030526 11037452, hotness: undefined, score: 4, children: 0
keystome 3 points 2 years ago

If your device gets compromised, it's no longer the company's problem.

path: 0 11030526 11042948, hotness: undefined, score: 3, children: 0
uis 1 point 2 years ago

lack encryption especially in the hands of a third party company managing your data

Are we still talking about local-only keys?

path: 0 11030526 11048632, hotness: undefined, score: 1, children: 0
WolfLink 1 point 2 years ago
path: 0 11030526 11041108, hotness: undefined, score: 1, children: 0
Midnight1938 0 points 2 years ago

I presume keys are already sort of encrypted?

path: 0 11030526 11032162, hotness: undefined, score: 0, children: 2
hexabs 6 points 2 years ago

Nope. Your presumption is wrong.

path: 0 11030526 11032162 11033116, hotness: undefined, score: 6, children: 1
Midnight1938 1 point 2 years ago

👍

path: 0 11030526 11032162 11033116 11033501, hotness: undefined, score: 1, children: 0
DemBoSain 27 points 2 years ago

Why is Signal almost universally defended whenever another security flaw is discovered? They're not secure, they don't address security issues, and their business model is unsustainable in the long term.

But, but, if you have malware "you have bigger problems". But, but, an attacker would have to have "physical access" to exploit this. Wow, such bullshit. Do some of you people really understand what you're posting?

But, but, "windows is compromised right out of the box". Yes...and?

But, but, "Signal doesn't claim to be secure". Fuck off, yes they do.

But, but, "just use disk encryption". Just...no...WTF?

Anybody using Signal for secure messaging is misguided. Any on of your recipients could be using the desktop app and there's no way to know unless they tell you. On top of that, all messages filter through Signal's servers, adding a single-point-of-failure to everything. Take away the servers, no more Signal.

path: 0 11028340, hotness: undefined, score: 27, children: 52
Zak 33 points 2 years ago

If someone can read my Signal keys on my desktop, they can also:

  • Replace my Signal app with a maliciously modified version
  • Install a program that sends the contents of my desktop notifications (likely including Signal messages) somewhere
  • Install a keylogger
  • Run a program that captures screenshots when certain conditions are met
  • [a long list of other malware things]

Signal should change this because it would add a little friction to a certain type of attack, but a messaging app designed for ease of use and mainstream acceptance cannot provide a lot of protection against an attacker who has already gained the ability to run arbitrary code on your user account.

path: 0 11028340 11028839, hotness: undefined, score: 33, children: 11
douglasg14b 17 points 2 years ago

Not necessarily.

https://en.m.wikipedia.org/wiki/Swiss_cheese_model

If you read anything, at least read this link to self correct.


This is a common area where non-security professionals out themselves as not actually being such: The broken/fallacy reasoning about security risk management. Generally the same "Dismissive security by way of ignorance" premises.

It's fundamentally the same as "safety" (Think OSHA and CSB) The same thought processes, the same risk models, the same risk factors....etc

And similarly the same negligence towards filling in holes in your "swiss cheese model".

"Oh that can't happen because that would mean x,y,z would have to happen and those are even worse"

"Oh that's not possible because A happening means C would have to happen first, so we don't need to consider this is a risk"

....etc

The same logic you're using is the same logic that the industry has decades of evidence showing how wrong it is.

Decades of evidence indicating that you are wrong, you know infinitely less than you think you do, and you most definitely are not capable of exhaustively enumerating all influencing factors. No one is. It's beyond arrogant for anyone to think that they could 🤦🤦 🤦

Thus, most risks are considered valid risks (this doesn't necessarily mean they are all mitigatable though). Each risk is a hole in your model. And each hole is in itself at a unique risk of lining up with other holes, and developing into an actual safety or security incident.

In this case

  • signal was alerted to this over 6 years ago
  • the framework they use for the desktop app already has built-in features for this problem.
    • this is a common problem with common solutions that are industry-wide.
  • someone has already made a pull request to enable the electron safe storage API. And signal has ignored it.

Thus this is just straight up negligence on their part.

There's not really much in the way of good excuses here. We're talking about a run of the mill problem that has baked in solutions in most major frameworks including the one signal uses.

https://www.electronjs.org/...

path: 0 11028340 11028839 11030931, hotness: undefined, score: 17, children: 2
fuzzzerd 4 points 2 years ago

I was just nodding along, reading your post thinking, yup, agreed. Until I saw there was a PR to fix it that signal ignored, that seems odd and there must be some mitigating circumstances on why they haven't merged it.

Otherwise that's just inexcusable.

path: 0 11028340 11028839 11030931 11032996, hotness: undefined, score: 4, children: 1
ChairmanMeow 7 points 2 years ago

The PR had some issues regarding files that were pushed that shouldn't have been, adding refactors that should have been in separate PRs, etc...

Though the main reason is that Signal doesn't consider this issue a part of their threat model.

path: 0 11028340 11028839 11030931 11032996 11036603, hotness: undefined, score: 7, children: 0
gomp 12 points 2 years ago

Those are outside Signal's scope and depend entirely on your OS and your (or your sysadmin's) security practices (eg. I'm almost sure in linux you need extra privileges for those things on top of just read access to the user's home directory).

The point is, why didn't the Signal devs code it the proper way and obtain the credentials every time (interactively from the user or automatically via the OS password manager) instead of just storing them in plain text?

path: 0 11028340 11028839 11029116, hotness: undefined, score: 12, children: 6
Zak 5 points 2 years ago

You'd need write access to the user's home directory, but doing something with desktop notifications on modern Linux is as simple as

dbus-monitor "interface='org.freedesktop.Notifications'" | grep --line-buffered "member=Notify\|string" | [insert command here]

Replacing the Signal app for that user also doesn't require elevated privileges unless the home directory is mounted noexec.

path: 0 11028340 11028839 11029116 11030498, hotness: undefined, score: 5, children: 0
douglasg14b 5 points 2 years ago

They're arguing a red herring. They don't understand security risk modeling, argument about signals scope let's their broken premise dig deeper. It's fundamentally flawed.

It's a risk and should be mitigated using common tools already provided by every major operating system (ie. Keychain).

path: 0 11028340 11028839 11029116 11030973, hotness: undefined, score: 5, children: 1
Liz 3 points 2 years ago

"Highways shouldn't have guard rails because if you hit one you've already gone off the road anyway."

path: 0 11028340 11028839 11029116 11030973 11031723, hotness: undefined, score: 3, children: 0
9tr6gyp3 -2 points 2 years ago

Feel free to submit a pull request. We could use your help.

path: 0 11028340 11028839 11029116 11029999, hotness: undefined, score: -2, children: 2
gomp 1 point 2 years ago

I don't see the reasoning in your answer (I do see its passive-aggressiveness, but chose to ignore it).

I asked "why?"; does your reply mean "because lack of manpower", "because lack of skill" or something else entirely?

In case you are new to the FOSS world, that being "open source" doesn't mean that something cannot be criticized or that people without the skill (or time!) to submit PRs must shut the fu*k up.

path: 0 11028340 11028839 11029116 11029999 11031734, hotness: undefined, score: 1, children: 1
refalo 2 points 2 years ago

(for Android) https://molly.im/ restores the encryption to this file and adds other useful things

path: 0 11028340 11028839 11030443, hotness: undefined, score: 2, children: 0
todd_bonzalez 7 points 2 years ago
path: 0 11028340 11037524, hotness: undefined, score: 7, children: 0
lemmyvore 4 points 2 years ago

Now replace "signal" in your comment with "ssh" and think it over.

path: 0 11028340 11035262, hotness: undefined, score: 4, children: 4
todd_bonzalez 6 points 2 years ago
path: 0 11028340 11035262 11037487, hotness: undefined, score: 6, children: 3
roguetrick 4 points 2 years ago

Ah the old Lemmy SHHwitcharoo.

path: 0 11028340 11035262 11037487 11039517, hotness: undefined, score: 4, children: 2
uis 1 point 2 years ago

SSHwitcharoo

path: 0 11028340 11035262 11037487 11039517 11048873, hotness: undefined, score: 1, children: 1
GlenRambo 4 points 2 years ago

Whats the next best alternative?

path: 0 11028340 11028415, hotness: undefined, score: 4, children: 17
Isoprenoid 14 points 2 years ago

Meeting in person.

path: 0 11028340 11028415 11028520, hotness: undefined, score: 14, children: 3
GlenRambo 7 points 2 years ago

I'll organise a time and place to meet in person via ... Carrier pigeon?

We're citizens raging against phones Lazlow.

path: 0 11028340 11028415 11028520 11030627, hotness: undefined, score: 7, children: 0
SendMePhotos 6 points 2 years ago

With a helicopter over you, loud music next to you, and a dude mowing next to you.

path: 0 11028340 11028415 11028520 11029565, hotness: undefined, score: 6, children: 1
nikaro 6 points 2 years ago

And no smartphone in your pocket, of course.

path: 0 11028340 11028415 11028520 11029565 11029740, hotness: undefined, score: 6, children: 0
refalo 6 points 2 years ago

That depends on your threat model. What are you worried about?

path: 0 11028340 11028415 11030913, hotness: undefined, score: 6, children: 0
ruse8145 3 points 2 years ago

Matrix or xmpp, bonus points with a personal server

Thanks to interest of late, the conversations and gajim apps have come a long way in recent years, and matrix has made good strides too with element-x

path: 0 11028340 11028415 11029572, hotness: undefined, score: 3, children: 8
GlenRambo 4 points 2 years ago

I'd tried matix but without a high level of technical experience it was pretty difficult to setup. I got as far as docker, that needed ansible, that wouldn't compile. I also recall there was services I could pay for, but then I'd rely on them to provide the security/servers.

Matrix doesn't seem for the majority of people taking a first step away from big tech.

path: 0 11028340 11028415 11029572 11030850, hotness: undefined, score: 4, children: 1
toastal 3 points 2 years ago

Snikket is meant to be super simple to self-host. Ejabberd has a web GUI that can make configuration easier.

path: 0 11028340 11028415 11029572 11030850 11035054, hotness: undefined, score: 3, children: 0
refalo 1 point 2 years ago

I would only ever suggest matrix if you're running a private self-hosted instance that is NOT federated, which you can do even easier with Signal anyways.

path: 0 11028340 11028415 11029572 11029856, hotness: undefined, score: 1, children: 4
ruse8145 2 points 2 years ago

That's fine, but why?

path: 0 11028340 11028415 11029572 11029856 11030184, hotness: undefined, score: 2, children: 3
uis 1 point 2 years ago

bonus points with a personal server

Only with appservices. Doesn't make sense otherwise.

path: 0 11028340 11028415 11029572 11048900, hotness: undefined, score: 1, children: 0
refalo 2 points 2 years ago path: 0 11028340 11028415 11029912, hotness: undefined, score: 2, children: 2
ivn 2 points 2 years ago

I can find the desktop client, am I missing something?

path: 0 11028340 11028415 11029912 11030402, hotness: undefined, score: 2, children: 1
refalo 3 points 2 years ago

You're right, there isn't one, my apologies; I edited the comment.

You could use some kind of encrypted container on the desktop though, or maybe run it as a separate user that has an encrypted home folder. The problem is you need to define a threat model first. Depending on what you're afraid of, any particular "solution" could either be way overkill, or never enough.

path: 0 11028340 11028415 11029912 11030402 11030861, hotness: undefined, score: 3, children: 0
refalo 4 points 2 years ago

98% of desktop apps (at least on Windows and Linux) are already broken by design anyways. Any one app can spy on and keylog all other apps, all your home folder data, everything. And anyone can write a desktop app, so only using solutions that (currently) don't have a desktop app version, seems silly to me.

path: 0 11028340 11029892, hotness: undefined, score: 4, children: 6
explore_broaden 5 points 2 years ago

I don’t think apps can read keystrokes for other apps on Wayland.

path: 0 11028340 11029892 11036667, hotness: undefined, score: 5, children: 3
possiblylinux127 2 points 2 years ago

Unless you have root

path: 0 11028340 11029892 11036667 11039257, hotness: undefined, score: 2, children: 1
explore_broaden 2 points 2 years ago

If you have root you could just update the kernel to one that lets you do whatever you want on the system, so there’s no way to stop the attacker from viewing the passwords if the app is capable of displaying them.

path: 0 11028340 11029892 11036667 11039257 11046847, hotness: undefined, score: 2, children: 0
refalo 1 point 2 years ago path: 0 11028340 11029892 11036667 11057874, hotness: undefined, score: 1, children: 0
AProfessional 5 points 2 years ago

Linux has a sandbox solution growing in popularity, flatpak.

path: 0 11028340 11029892 11031505, hotness: undefined, score: 5, children: 1
possiblylinux127 4 points 2 years ago

And Wayland. Xorg is a complete and utter mess

path: 0 11028340 11029892 11031505 11039251, hotness: undefined, score: 4, children: 0
possiblylinux127 3 points 2 years ago

I hope you are joking

path: 0 11028340 11039255, hotness: undefined, score: 3, children: 0
dessalines 2 points 2 years ago

Basically for the same reason people often defend apple: the user interface is shiny, and they claim to be privacy oriented.

Signal is a centralized US hosted service, that alone should be enough to disqualify it, outside of our many other criticisms.

path: 0 11028340 11042274, hotness: undefined, score: 2, children: 0
uis 0 points 2 years ago

But, but, "just use disk encryption". Just...no...WTF?

So not encrypting keys is bad, but actually encrypting them is bad too? Ok.

Any on of your recipients could be using the desktop app and there's no way to know unless they tell you.

Another applefan? How it THIS supposed to be in scope of E2EE? Moreover, how having a way to know if recepient is using desktop app is not opposite of privacy?

On top of that, all messages filter through Signal's servers, adding a single-point-of-failure to everything. Take away the servers, no more Signal.

Indeed. This is why I use Matrix. Also, fuck showing phone numbers to everyone(I heard they did something about it) and registration with phone numbers.

path: 0 11028340 11048864, hotness: undefined, score: 0, children: 3
DemBoSain 0 points 2 years ago

Any "secure" so that relies on someone else for security is not secure.

Fuck the scope of E2EE. Signal makes a lot of claims on their website that are laughable. The desktop app is their main weakness. Attachments are stored unencrypted, keys in plaintext. If they were serious about security, they would depricate the windows app and block it from their servers.

WTF does Apple have to do with anything?

path: 0 11028340 11048864 11055874, hotness: undefined, score: 0, children: 2
uis 0 points 2 years ago

Any "secure" so that relies on someone else for security is not secure.

Fuck the scope of E2EE.

When someone has FSB/NSA agent behind them reading messages, no amount of encryption will help. Biggest cybersecurity vulnreability is located between monitor and chair. When you are texting someone else, that someone else's chair-monitor space is also vulnreable.

Signal makes a lot of claims on their website that are laughable.

Well, maybe. I didn't read their claims, nor I use signal.

Attachments are stored unencrypted, keys in plaintext.

Is OS-level encryption plaintext or not? If yes, then they are encrypted, provided user enables such feature in OS. If not - nothing if encrypted fundamentally.

If they were serious about security, they would depricate the windows app and block it from their servers.

WTF does Apple have to do with anything?

You just used applefans' argument. Yeah, I wonder what.

path: 0 11028340 11048864 11055874 11061575, hotness: undefined, score: 0, children: 1
DemBoSain 0 points 2 years ago

Well, maybe. I didn't read their claims, nor I use signal.

Your opinions are invalid.

path: 0 11028340 11048864 11055874 11061575 11080364, hotness: undefined, score: 0, children: 0
SeattleRain -5 points 2 years ago

What app stops a pre install keylogger. I'm all for hearing criticism of Signal but it's always about things they can't control.

path: 0 11028340 11028494, hotness: undefined, score: -5, children: 2
DemBoSain 3 points 2 years ago

They can't control if the encryption keys are stored in plaintext?

path: 0 11028340 11028494 11031296, hotness: undefined, score: 3, children: 1
SeattleRain 1 point 2 years ago

Ok I didn't mean that in particular

path: 0 11028340 11028494 11031296 11031933, hotness: undefined, score: 1, children: 0
jsomae 24 points 2 years ago

The real problem is that the security model for apps on mobile is much better than that for apps on desktop. Desktop apps should all have private storage that no other non-root app can access. And while we're at it, they should have to ask permission before activating the mic or camera.

path: 0 11024489, hotness: undefined, score: 24, children: 7
Cuntessera 9 points 2 years ago

macOS has nailed it*, even though it’s still not as good as iOS or Android, but leagues and bounds better than Windows and especially Linux.

ETC: *sandboxing/permission system

path: 0 11024489 11025112, hotness: undefined, score: 9, children: 4
Vash63 6 points 2 years ago

What's wrong with the Flatpak permissions system on Linux?

path: 0 11024489 11025112 11027842, hotness: undefined, score: 6, children: 1
Cuntessera 4 points 2 years ago

It’s a joke. Apps have defined permissions already allowed on install and some of them have too many things set to allow like home or host access. Also, changing any permission requires restarting the app. It’s heading in the right direction, but it has a looooong way to go to catch up with macOS, let alone Android and iOS.

path: 0 11024489 11025112 11027842 11028000, hotness: undefined, score: 4, children: 0
tmpod 3 points 2 years ago

What does Windows do? Genuine question, I've not used it since the 7 days. Regarding Linux, that's true for stuff installed through regular package managers and whatnot, but Flatpak is pushing a more sandboxed and permission oriented system, akin to Android.

path: 0 11024489 11025112 11028022, hotness: undefined, score: 3, children: 1
ruse8145 3 points 2 years ago

You have granular control over universal windows apps (ie windows 8+ apps) and one global lock over all desktop apps (non uwp), and one global lock over everything. It's pretty solid considering how little control Microsoft has and it's wonderful fetish for compatibility.

Tldr basically same as Linux, except app distribution in Linux was bad enough for so long that more stuff is in the new restricted format while windows still has tons of things which will never go away and aren't in the sandbox. I think not finding a way to sandbox all desktop apps was a mistake.

path: 0 11024489 11025112 11028022 11029737, hotness: undefined, score: 3, children: 0
refalo 3 points 2 years ago

Firejail and bwrap. Flatpaks. There are already ways to do this, but I only know of one distro that separates apps by default like Android does (separate user per app), which is the brand new "EasyOS".

path: 0 11024489 11030655, hotness: undefined, score: 3, children: 0
possiblylinux127 3 points 2 years ago

They do sort of with Flatpak

path: 0 11024489 11025963, hotness: undefined, score: 3, children: 0
mlg 22 points 2 years ago

Bruh windows and linux have a secrets vault (cred manager and keyring respectively, iirc) for this exact purpose.

Even Discord uses it on both OSs no problem

path: 0 11030646, hotness: undefined, score: 22, children: 0
ExtremeDullard 21 points 2 years ago

Whatever its stores and however it stores it doesn't matter to me: I moved its storage space to my ~/.Private encrypted directory. Same thing for my browser: I don't use a master password or rely on its encryption because I set it up so it too saves my profile in the ~/.Private directory.

See here for more information. You can essentially secure any data saved by any app with eCryptfs - at least when you're logged out.

Linux-only of course. In Windows... well, Windows.

path: 0 11042651, hotness: undefined, score: 21, children: 1
uis 3 points 2 years ago

Or ext4 encrytion. Which is overpowered. You can have different keys for different files and directories.

path: 0 11042651 11048607, hotness: undefined, score: 3, children: 0
sntx 20 points 2 years ago

I have three things to say:

  1. Everyone, please make sure you've set up sound disk encryption
  2. That's not a suprise (for me at least)
  3. It's not much different on mobile (db is unecrypted) - check out molly (signal fork) if you want to encrypt it. However encrypted db means no messages until you decrypt it.
path: 0 11036891, hotness: undefined, score: 20, children: 0
notannpc 14 points 2 years ago

This just in: threat actors compromising your devices is bad. More at 11.

path: 0 11026967, hotness: undefined, score: 14, children: 2
notannpc 5 points 2 years ago

Obviously the keys could be stored more securely, but if you’ve got malware on your machine that can exploit this you’ve already got bigger problems.

path: 0 11026967 11026990, hotness: undefined, score: 5, children: 1
douglasg14b -3 points 2 years ago

That's not how this works.

This sort of "dismissive security through ignorance" is how we get so many damn security breaches these days.

I see this every day with software engineers, a group that you would think would be above the bar on security. Unfortunately a little bit of knowledge results in a mountain of confidence (see Dunning Kruger effect). They are just confident in bad choices instead.

"We don't need to use encryption at rest because if the database is compromised we have bigger problems" really did a lot to protect the last few thousand companies from preventable data exfiltration that was in fact the largest problem they had.

Turns out that having read access to the underlying storage for the database doesn't necessarily mean that the database and all of your internal systems are more compromised. It just means that the decision makers were making poor decisions based on a lack of risk modeling knowledge.


That said the real question I have for you here is:

Are you confident in your omniscience in that you can enumerate all risks and attack factors that can result in data being exfiltrated from a device?

If not, then why comment as if you are?

path: 0 11026967 11026990 11031235, hotness: undefined, score: -3, children: 0
Majestic 11 points 2 years ago
path: 0 11033084, hotness: undefined, score: 11, children: 6
possiblylinux127 10 points 2 years ago

To encrypt it you would need to store a encryption key

path: 0 11033084 11039188, hotness: undefined, score: 10, children: 2
rmuk 6 points 2 years ago

It's plaintext all the way down.

path: 0 11033084 11039188 11040918, hotness: undefined, score: 6, children: 0
Kajika 3 points 2 years ago

The irony

path: 0 11033084 11039188 11039622, hotness: undefined, score: 3, children: 0
uis 1 point 2 years ago

for not even salting

Wrong secret

path: 0 11033084 11048529, hotness: undefined, score: 1, children: 2
Majestic 1 point 2 years ago

I mean combined with any kind of function, even a trivial kind. A salt derived from some machine state data (a random install id generated on install, a hash of computer name, etc) plus a rot13 or something would still be better than leaving it plaintext.

path: 0 11033084 11048529 11064669, hotness: undefined, score: 1, children: 1
uis 1 point 2 years ago

Malware has access to it.

If fs is not encrypted, then malicious hardware(FSB agent's laptop) also has access to it. If encrypted, then it we are back to statement many people told here about encrypting fs.

plus a rot13

That's not salting.

path: 0 11033084 11048529 11064669 11065562, hotness: undefined, score: 1, children: 0
possiblylinux127 4 points 2 years ago

They could just add a password

path: 0 11025994, hotness: undefined, score: 4, children: 0
delirious_owl 3 points 2 years ago

Wire does this too :/

path: 0 11032283, hotness: undefined, score: 3, children: 9
refalo 2 points 2 years ago

What is Wire?

path: 0 11032283 11032951, hotness: undefined, score: 2, children: 4
southsamurai 4 points 2 years ago

A different encrypted messaging service. Decent, but hasn't taken off despite using email for accounts rather than phone bonkers numbers

path: 0 11032283 11032951 11033706, hotness: undefined, score: 4, children: 3
Mubelotix 0 points 2 years ago
path: 0 11032283 11032951 11033706 11035775, hotness: undefined, score: 0, children: 2
southsamurai 3 points 2 years ago

I mean, not really.

Which standard are they going to be forced to use? What infrastructure? What encryption? Are they going to be forced to develop apps for every platform?

The best you can hope to expect is apps using the same standard being compatible. Xmpp, matrix, whisper, whatever. Even matrix bridges don't really fix compatibility across standards very well.

It's nice to think that anyone anywhere, could expect to install any app and communicate with anyone else and maintain encryption as well as full privacy. But as far as anyone I've ever seen talk about it that's actually trained in the technology behind it all, it isn't possible unless there's a single, enforced standard in use.

Does it suck to have to deal with multiple apps? Hell yes. But I also don't like the idea of being forced to use whatever compromise protocol would make it realistic. I'd rather have a dozen apps with no single gatekeeper between them.

path: 0 11032283 11032951 11033706 11035775 11036159, hotness: undefined, score: 3, children: 1
possiblylinux127 1 point 2 years ago

Don't use Wire as it isn't good for privacy or security

path: 0 11032283 11039189, hotness: undefined, score: 1, children: 3
delirious_owl 1 point 2 years ago

Don't use signal as its not good for anonymity

path: 0 11032283 11039189 11039336, hotness: undefined, score: 1, children: 2
possiblylinux127 1 point 2 years ago

It is better than Wire and cryptography wise it is very solid

path: 0 11032283 11039189 11039336 11039723, hotness: undefined, score: 1, children: 1
delirious_owl 1 point 2 years ago

Wire has equal cryptography, but it also has anonymity. I don't understand why anyone uses signal.

For the Sticker emojis, I guess

Neither encrypts keys on desktop. They really are both about equal with regard to crypto

path: 0 11032283 11039189 11039336 11039723 11042464, hotness: undefined, score: 1, children: 0
brayd 1 point 2 years ago

Does anyone know how iMessage handles this on desktop (on Macs) as they (as far as I know) upgraded their encryption recently?

path: 0 11028916, hotness: undefined, score: 1, children: 1
bloodfart 1 point 2 years ago

It’s handled through keyring I think.

path: 0 11028916 11040980, hotness: undefined, score: 1, children: 0
01189998819991197253 1 point 2 years ago

Couldn't they set up a 2fa, where it sends a notification to your mobile Signal (since you must have that anyway, to use desktop)? If you want to decrypt your Desktop Signal, you need to allow it on your Mobile Signal.

path: 0 11040965, hotness: undefined, score: 1, children: 0
kbal 1 point 2 years ago

Alternative headline: Someone has a feature request for Signal which would be of interest to a few people with very specific security needs.

path: 0 11025167, hotness: undefined, score: 1, children: 16
AbidanYre 7 points 2 years ago

You mean the types of people who would use signal to communicate with others?

path: 0 11025167 11026005, hotness: undefined, score: 7, children: 0
communism 4 points 2 years ago

It's not a bad feature to ensure that eg if there's a malicious process running on your computer it can't send all your signal data to whomever

path: 0 11025167 11025427, hotness: undefined, score: 4, children: 14
kbal 2 points 2 years ago

Needing to enter a secure passphrase each time you want to use signal in exchange for one more fragile layer of defence for that one part of your data in a scenario that would normally mean you've already lost unless you're running a super-secure compartmentalized operating system like qubes or something is probably not worth it for most people.

path: 0 11025167 11025427 11026541, hotness: undefined, score: 2, children: 13
communism 1 point 2 years ago

I already enter a passphrase every time I want to use Signal; I use the Molly client on my phone. It's really not a big deal. I also enter a passphrase every time I launch my password manager, every time I launch my two-factor authentication app on my phone, and every time I open my email client. I think it's fairly standard to protect sensitive data on your computer with encryption at rest and to decrypt it upon launching the application that handles the data.

path: 0 11025167 11025427 11026541 11027097, hotness: undefined, score: 1, children: 12
refalo 5 points 2 years ago

It’s really not a big deal

For most casual users, it is a deal-breaker. And it's hard to get everyday people to use your software with roadblocks like that.

every time I open my email client.

You must not get email very often, this is absolutely a non-starter for me.

path: 0 11025167 11025427 11026541 11027097 11030700, hotness: undefined, score: 5, children: 1
kbal 3 points 2 years ago

Huh. I would've thought most desktop users just leave it running all day long like I do. Obviously there is the disk encryption passphrase at boot, adding another one for signal would in my case be redundant.

But the point is not only how easy it is to enter a passphrase, but also how much security that actually gains you. I don't think it does much on the typical desktop, be it windows or linux, where there are so many ways to escalate or persist privilege for anyone that has user-level access.

path: 0 11025167 11025427 11026541 11027097 11027123, hotness: undefined, score: 3, children: 3
tmpod 0 points 2 years ago

This has nothing to do with the mobile app, which also has password/biometric unlocking, it's about the desktop electron app.

path: 0 11025167 11025427 11026541 11027097 11027795, hotness: undefined, score: 0, children: 5
unrushed233 -2 points 2 years ago

Can we please all just acknowledge that desktop operating systems absolutely suck (in regards to security)?

path: 0 11031618, hotness: undefined, score: -2, children: 3
leanleft 1 point 2 years ago

This is what flatpak brings to the table

path: 0 11031618 11127779, hotness: undefined, score: 1, children: 0
doodledup 1 point 2 years ago

How is a Desktop OS any different from a mobile one? This is where you need to be more specific.

path: 0 11031618 11034026, hotness: undefined, score: 1, children: 1
thayer 7 points 2 years ago

There are too many differences for me to list here, but unlike mobile operating systems, Windows and most Linux desktops do not provide sandboxed environments for userspace apps by default. Apps generally have free reign over the whole system; reading/writing data from/to other apps without restriction or notification. There are virtually no safeguards against malicious actors.

Mobile operating systems significantly restrict system-level storage space, making key areas read-only to prevent data access or manipulation. They also protect app storage, so one app can't arbitrarily access or modify data stored for a different app.

Mobile operating systems also follow an image-based update model, wherein updates are atomic. System software updates are generally applied successfully all at once or not at all, helping to ensure your phone is never left in a partial or unusable state after a system update.

For desktop users, macOS, and atomic Linux distros combined with Flatpak are the closest comparisons.

path: 0 11031618 11034026 11034340, hotness: undefined, score: 7, children: 0
GENTLEMANNEofLEISURE -3 points 2 years ago

dawg what the shitfuck

path: 0 11030273, hotness: undefined, score: -3, children: 0
ssm -6 points 2 years ago

So many better standards like XMPP and IRC yet people use Signal and Telegram. I hate marketing.

path: 0 11027003, hotness: undefined, score: -6, children: 1
ruse8145 -1 points 2 years ago

Signal is an objectively better experience than xmpp, and has about identical security (same with matrix). Irc isn't secure afaik. Telegram isn't secure afaik.

A better wish would be that people in 2024 would stop being fuckign weird about their cell number. Some people don't want to give it out despite white pages being the standard for years (and how the Terminator knows who to kill). Other people refuse to use a messaging app where they can't use their phone to sign up. Some people want to sign up with their number but not give it out.

path: 0 11027003 11029640, hotness: undefined, score: -1, children: 0
mtchristo -11 points 2 years ago

You are telling me this has been going on for almost a decade now, and no one ever noticed ?

So we trust open source apps under the premise that if malicious code gets added to the code, at least one person will notice ? Here it shows that years pass before anyone notices and millions of people's communications could have been compromised by the world's most trusted messaging app.

I don't know which app to trust after this, if any?

path: 0 11035689, hotness: undefined, score: -11, children: 4
Mubelotix 19 points 2 years ago

Everyone knew that already tbh

path: 0 11035689 11035707, hotness: undefined, score: 19, children: 0
possiblylinux127 5 points 2 years ago

Why is this a shock? Someone would need to have already compromised your device. Even if it was encrypted with a password they still could install a key logger

path: 0 11035689 11039162, hotness: undefined, score: 5, children: 1
mtchristo 0 points 2 years ago

It is easier to compromise a device than to try and compromise encrypted communications.

path: 0 11035689 11039162 11041447, hotness: undefined, score: 0, children: 0
derpgon 0 points 2 years ago

Matrix. You can host any version you want, and when you have to update, just do a version diff between you current and latest versions and check yourself.

path: 0 11035689 11036829, hotness: undefined, score: 0, children: 0
istanbullu -11 points 2 years ago

Signal has so many red flags that I'm beginning to wonder if it is a honeypot.

path: 0 11028751, hotness: undefined, score: -11, children: 8
Bogasse 5 points 2 years ago

What other red flags do you have in mind?

path: 0 11028751 11029055, hotness: undefined, score: 5, children: 6
istanbullu 2 points 2 years ago

Signal is actively hostile to alternative clients, or decoupling from Google.

path: 0 11028751 11029055 11035705, hotness: undefined, score: 2, children: 0
livestreamedcollapse -2 points 2 years ago

Back when the Signal org used to be called Open Whisper Systems it received grants and auditing from the Open Technology Fund which, at the time, was still a part of Radio Free Asia.

https://web.archive.org/...

path: 0 11028751 11029055 11029347, hotness: undefined, score: -2, children: 4
ruse8145 11 points 2 years ago

So tldr, since you didn't finish your thought, is that they got a grant like 3+ layers down, from the US government.

I have some news for you, or perhaps I can offer you a bridge.

path: 0 11028751 11029055 11029347 11029559, hotness: undefined, score: 11, children: 3
livestreamedcollapse -3 points 2 years ago

People are free to draw their own conclusions from it. Do you have anything material to contribute, or will you just be putting more smarmy words in my mouth from here on out?

path: 0 11028751 11029055 11029347 11029559 11029646, hotness: undefined, score: -3, children: 2
refalo 2 points 2 years ago

Got some sources for that, chief?

path: 0 11028751 11030495, hotness: undefined, score: 2, children: 0

thanks for using Leebra!

go to feed...