Am I tripping or if you upgrade Signal Desktop, it saves all your messages in plain text (messages.json) + attachments locally so you can re-import them in the newer version? #fail #wtf
If you want encryption at rest against external attackers, *use FDE*. If you want security across app boundaries, *use different users or sandboxing*. There are much better solutions to real attack scenarios than Signal throwing some random crypto onto its backups.
-
-
You've successfully exhausted me. The last thing I'll say is: most desktop systems do not isolate apps as individual users, even though they should. The model of "once an attacker has access to a userspace, stop even trying" is not legit, though I do understand deprioritizing it.
-
They should, and this is not something for *Signal* to fix. It's something for OSes to fix (and some do, for some subset of apps, and then Signal doesn't have to care since its backup file should be isolated too).
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.