Nemeski@lemm.ee to Privacy Guides@lemmy.oneEnglish · 4 months agoSignal under fire for storing encryption keys in plaintextstackdiary.comexternal-linkmessage-square49fedilinkarrow-up1214arrow-down10cross-posted to: cybersecurity@sh.itjust.workstechnology@lemmy.worldfoss@beehaw.org
arrow-up1214arrow-down1external-linkSignal under fire for storing encryption keys in plaintextstackdiary.comNemeski@lemm.ee to Privacy Guides@lemmy.oneEnglish · 4 months agomessage-square49fedilinkcross-posted to: cybersecurity@sh.itjust.workstechnology@lemmy.worldfoss@beehaw.org
minus-squarebreadsmasher@lemmy.worldlinkfedilinkEnglisharrow-up121·4 months ago on desktop devices Kinda should have been in the headline
minus-squareTramort@programming.devlinkfedilinkEnglisharrow-up45·4 months agoIt is a super important detail, but it’s still unforgivable for an app that expects privacy to be part of its brand identity.
minus-squarebreadsmasher@lemmy.worldlinkfedilinkEnglisharrow-up8·4 months ago unforgivable yeah absolutely agreed
minus-squarebrakebreaker101@lemmy.worldlinkfedilinkEnglisharrow-up3·4 months agoThis is a big difference between privacy and security.
minus-squareTramort@programming.devlinkfedilinkEnglisharrow-up3·4 months agoAgreed But you can’t have privacy without security, and any privacy brand must have security in their bones.
minus-squareclaudiop@lemmy.worldlinkfedilinkEnglisharrow-up7·4 months agoYou can’t encrypt anything without a key. This is the key. If it wasn’t in plaintext then it would be encrypted. Then you’d need a key for that. Where do you put it? Phone OSs have mechanisms to solve this. Desktop ones do not.
Kinda should have been in the headline
It is a super important detail, but it’s still unforgivable for an app that expects privacy to be part of its brand identity.
yeah absolutely agreed
This is a big difference between privacy and security.
Agreed
But you can’t have privacy without security, and any privacy brand must have security in their bones.
You can’t encrypt anything without a key. This is the key. If it wasn’t in plaintext then it would be encrypted. Then you’d need a key for that. Where do you put it?
Phone OSs have mechanisms to solve this. Desktop ones do not.