• mipadaitu@lemmy.world
      link
      fedilink
      English
      arrow-up
      35
      arrow-down
      2
      ·
      5 months ago

      Aside from needing a passkey/passphrase every time you open Signal, what would be the solution? If the user can read the unencrypted messages, then so can malware running as the user.

      Heck, even if you required some sort of authentication to open the messages, malware could just capture that.

      It’s the same problem with browser credential stealing, you can grab all the cookies from an authenticated browser session and copy it to a new system.

      Really, the biggest issue is that Signal doesn’t detect multiple instances running of the same session, but that’s also extremely difficult to do without malware being able to work around it.

      Not saying there’s no solution here, but there is not a simple solution aside from trusting your computer and cancelling sessions if you suspect someone compromised your system (or just not using a desktop app.)

      • sugar_in_your_tea@sh.itjust.works
        link
        fedilink
        arrow-up
        16
        arrow-down
        2
        ·
        edit-2
        5 months ago

        malware could just capture that

        From the article:

        This means that while a keylogger might require admin access to install, any app or script with sufficient permissions could access these plaintext keys.

        Malware to capture input would require privilege escalation as well, whereas this just requires being able to run code/copy files.

        there is not a simple solution

        But there are:

        • use the system keyring
        • store unencrypted key in memory in a background process (I.e. DIY keyring)

        Essentially, force malware to either copy keystrokes or memory, both of which require admin privileges on most systems.

      • m-p{3}A
        link
        fedilink
        arrow-up
        11
        ·
        5 months ago

        Storing the encryption keys in the Credentials Manager (Windows) or the Keychain (macOS, Linux) would be a better choice than a plaintext file.

        And using Bitlocker / VeraCrypt / Filevault / LUKS will at least protect the data at rest.

        But as you said, it’s game over if the machine is compromised.

          • AnotherDirtyAnglo
            link
            fedilink
            arrow-up
            2
            ·
            5 months ago

            On Macs, there is a ‘keychain’ where certificates and passwords are stored encrypted, and there are OS-level controls on access – either an OS prompt for a password, or biometric authentication.

            • TheEntity@lemmy.world
              link
              fedilink
              arrow-up
              1
              ·
              5 months ago

              My point was that apart from the Macs, there is no single system keychain Signal could use. What they do is perfectly normal and expected on a desktop OS.

      • drdiddlybadger@pawb.social
        link
        fedilink
        arrow-up
        6
        arrow-down
        2
        ·
        5 months ago

        Agreed. If your system is compromised you have other issues and ultimately that falls on you. And on Linux you could very well set permissions yourself for those directories.

  • psvrh
    link
    fedilink
    arrow-up
    4
    ·
    5 months ago

    Doesn’t… doesn’t then OpenSSH client store keys in text files?

    I’m trying to figure out how this is an issue, other than maybe Signal should be using an OS level keystore.

    • Jerkface (any/all)
      link
      fedilink
      English
      arrow-up
      1
      ·
      5 months ago

      They are text files but they are not “plaintext”. They are (optionally) encrypted with a user-supplied password. That is why you need ssh-agent to stay sane.

  • Beaver
    link
    fedilink
    English
    arrow-up
    4
    arrow-down
    1
    ·
    5 months ago

    Time to switch to matrix

  • DebatableRaccoon
    link
    fedilink
    arrow-up
    5
    arrow-down
    8
    ·
    5 months ago

    You come to expect better but then you can only roll your eyes and face-palm when even “the best” do something this stupid.

    • alsimoneau
      link
      fedilink
      arrow-up
      7
      arrow-down
      2
      ·
      5 months ago

      To be fair it’s on your own device, not the server.