Am I tripping or if you upgrade Signal Desktop, it saves all your messages in plain text (messages.json) + attachments locally so you can re-import them in the newer version? #fail #wtf
Throwing encryption at a wall to see what sticks isn't "defense in depth". Defense in depth is adding layers of security on a solid foundation. Putting crypto bullet points up on a slide isn't DiD, it's how Sony builds game console security and look how well that worked.
-
-
And if you're talking about keys stored in memory being useless, you're also sort of implying old fashioned, non-PFS style encryption is useless. Anyway, you're being condescending and it's annoying. Encryption at rest isn't "magic pixie dust" or "throwing encryption at a wall".
-
You keep trying to straw man me. I never said encryption at rest is useless. I said you need to know your threat model. Encryption at rest is only useful when (attack surface of storage) > (attack surface of active system).
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.