Am I tripping or if you upgrade Signal Desktop, it saves all your messages in plain text (messages.json) + attachments locally so you can re-import them in the newer version? #fail #wtf
Of course you can concoct artificial scenarios where encryption at rest helps on a desktop, but the benefit is *minimal*, won't stop a dedicated attacker, and thus Signal not encrypting at rest backups on a desktop is not a WTF.
-
-
If you want encryption at rest against external attackers, *use FDE*. If you want security across app boundaries, *use different users or sandboxing*. There are much better solutions to real attack scenarios than Signal throwing some random crypto onto its backups.
-
You've successfully exhausted me. The last thing I'll say is: most desktop systems do not isolate apps as individual users, even though they should. The model of "once an attacker has access to a userspace, stop even trying" is not legit, though I do understand deprioritizing it.
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.