Am I tripping or if you upgrade Signal Desktop, it saves all your messages in plain text (messages.json) + attachments locally so you can re-import them in the newer version? #fail #wtf
-
-
Replying to @msuiche
There is no magical pixie dust encryption algorithm that will protect your messages in such a way that whatever new version of Signal can access them but no other app or user can (on a desktop). If you have local access it's game over.
5 replies 1 retweet 12 likes -
any such challenge can be resolved by a dev who actually takes time to address it
1 reply 0 retweets 0 likes -
Security is more than just the dev's job. How would a dev account for me giving out my passwords to everyone?
1 reply 0 retweets 0 likes -
Would it not be safe to assume people chosing privacy tools have no intent on sharing passwords with just everyone. They'd use a post-it. As long as the devs don't supply the tools to get the job done in a way that gets the job done. Security is a waste of time, and it often is.
1 reply 0 retweets 0 likes -
There's tools to encrypt hard drives already so the question becomes why we can trust security conscious people to not hand out passwords but also cant trust them to run bitlocker?
2 replies 0 retweets 0 likes -
What does harddrive encryption have to do with anything ? This is about signal not handling data in a trusted way.
2 replies 0 retweets 0 likes -
There is no way for Signal to handle data in a more trusted way that isn't better (or only) achieved with other tools. Please state exactly what your threat model is and how you think Signal encrypting its messages file would help.
1 reply 0 retweets 0 likes -
What is the point of signal if it does NOT encrypt the message file. Even the registration lock pincode as password would be better than plain text. If you don't exclude the folder chances are all those contents get indexed before you know it.
1 reply 0 retweets 0 likes
Again, please state exactly what you think that encryption would achieve. What attack are you trying to prevent?
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.