minigubben's lemmy
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
ForgottenFlux@lemmy.world to Privacy@lemmy.mlEnglish · 1 year ago

Signal under fire for storing encryption keys in plaintext on desktop app

stackdiary.com

external-link
message-square
258
fedilink
  • cross-posted to:
  • privacy@lemmy.world
  • technology@lemmy.world
  • foss@beehaw.org
482
external-link

Signal under fire for storing encryption keys in plaintext on desktop app

stackdiary.com

ForgottenFlux@lemmy.world to Privacy@lemmy.mlEnglish · 1 year ago
message-square
258
fedilink
  • cross-posted to:
  • privacy@lemmy.world
  • technology@lemmy.world
  • foss@beehaw.org
Signal under fire for storing encryption keys in plaintext
stackdiary.com
external-link
Popular encrypted messaging app Signal is facing criticism over a security issue in its desktop application. Researchers and app users are raising
  • refalo@programming.dev
    link
    fedilink
    arrow-up
    9
    arrow-down
    3
    ·
    edit-2
    1 year ago

    98% of desktop apps (at least on Windows and Linux) are already broken by design anyways. Any one app can spy on and keylog all other apps, all your home folder data, everything. And anyone can write a desktop app, so only using solutions that (currently) don’t have a desktop app version, seems silly to me.

    • AProfessional@lemmy.world
      link
      fedilink
      English
      arrow-up
      7
      arrow-down
      2
      ·
      1 year ago

      Linux has a sandbox solution growing in popularity, flatpak.

      • Possibly linux@lemmy.zip
        link
        fedilink
        English
        arrow-up
        4
        ·
        1 year ago

        And Wayland. Xorg is a complete and utter mess

    • explore_broaden@midwest.social
      link
      fedilink
      arrow-up
      5
      ·
      1 year ago

      I don’t think apps can read keystrokes for other apps on Wayland.

      • Possibly linux@lemmy.zip
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 year ago

        Unless you have root

        • explore_broaden@midwest.social
          link
          fedilink
          arrow-up
          2
          ·
          1 year ago

          If you have root you could just update the kernel to one that lets you do whatever you want on the system, so there’s no way to stop the attacker from viewing the passwords if the app is capable of displaying them.

      • refalo@programming.dev
        link
        fedilink
        arrow-up
        2
        ·
        edit-2
        11 months ago

        Wayland doesn’t magically make other kinds of keyloggers stop working altogether though.

        https://old.reddit.com/r/linux/comments/23mj49/wayland_is_not_immune_to_keyloggers/

        https://github.com/Aishou/wayland-keylogger

        https://github.com/schauveau/sway-keylogger

        https://old.reddit.com/r/kde/comments/11h5tvl/wayland_security_keyloggers_are_back/

Privacy@lemmy.ml

privacy@lemmy.ml

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !privacy@lemmy.ml

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
  • Don’t promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

  • Lemmy.ml libre_culture
  • Lemmy.ml privatelife
  • Lemmy.ml DeGoogle
  • Lemmy.ca privacy

much thanks to @gary_host_laptop for the logo design :)

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 229 users / day
  • 2.83K users / week
  • 4.54K users / month
  • 7.39K users / 6 months
  • 1 local subscriber
  • 38.8K subscribers
  • 3.53K Posts
  • 87K Comments
  • Modlog
  • mods:
  • k_o_t@lemmy.ml
  • tmpod@lemmy.pt
  • Yayannick@lemmy.ml
  • ranok@sopuli.xyz
  • BE: 0.19.7
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org