PLG Social
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
ForgottenFlux@lemmy.world to Privacy@lemmy.mlEnglish · 11 months ago

Signal under fire for storing encryption keys in plaintext on desktop app

stackdiary.com

external-link
message-square
227
link
fedilink
  • cross-posted to:
  • privacy@lemmy.world
  • foss@beehaw.org
  • privacyguides@lemmy.one
456
external-link

Signal under fire for storing encryption keys in plaintext on desktop app

stackdiary.com

ForgottenFlux@lemmy.world to Privacy@lemmy.mlEnglish · 11 months ago
message-square
227
link
fedilink
  • cross-posted to:
  • privacy@lemmy.world
  • foss@beehaw.org
  • privacyguides@lemmy.one
Signal under fire for storing encryption keys in plaintext
stackdiary.com
external-link
Popular encrypted messaging app Signal is facing criticism over a security issue in its desktop application. Researchers and app users are raising
  • GlenRambo@jlai.lu
    link
    fedilink
    arrow-up
    3
    ·
    11 months ago

    Whats the next best alternative?

    • Isoprenoid@programming.dev
      link
      fedilink
      English
      arrow-up
      17
      arrow-down
      2
      ·
      11 months ago

      Meeting in person.

      • SendMePhotos@lemmy.world
        link
        fedilink
        arrow-up
        6
        ·
        11 months ago

        With a helicopter over you, loud music next to you, and a dude mowing next to you.

        • nikaro@jlai.lu
          link
          fedilink
          arrow-up
          5
          ·
          11 months ago

          And no smartphone in your pocket, of course.

      • GlenRambo@jlai.lu
        link
        fedilink
        arrow-up
        7
        arrow-down
        1
        ·
        11 months ago

        I’ll organise a time and place to meet in person via … Carrier pigeon?

        We’re citizens raging against phones Lazlow.

    • refalo@programming.dev
      link
      fedilink
      arrow-up
      6
      ·
      11 months ago

      That depends on your threat model. What are you worried about?

    • ruse8145@lemmy.sdf.org
      link
      fedilink
      arrow-up
      5
      arrow-down
      3
      ·
      edit-2
      11 months ago

      Matrix or xmpp, bonus points with a personal server

      Thanks to interest of late, the conversations and gajim apps have come a long way in recent years, and matrix has made good strides too with element-x

      • GlenRambo@jlai.lu
        link
        fedilink
        arrow-up
        4
        ·
        11 months ago

        I’d tried matix but without a high level of technical experience it was pretty difficult to setup. I got as far as docker, that needed ansible, that wouldn’t compile. I also recall there was services I could pay for, but then I’d rely on them to provide the security/servers.

        Matrix doesn’t seem for the majority of people taking a first step away from big tech.

        • toastal@lemmy.ml
          link
          fedilink
          arrow-up
          2
          ·
          11 months ago

          Snikket is meant to be super simple to self-host. Ejabberd has a web GUI that can make configuration easier.

      • refalo@programming.dev
        link
        fedilink
        arrow-up
        4
        arrow-down
        2
        ·
        edit-2
        11 months ago

        I would only ever suggest matrix if you’re running a private self-hosted instance that is NOT federated, which you can do even easier with Signal anyways.

        • ruse8145@lemmy.sdf.org
          link
          fedilink
          arrow-up
          1
          ·
          11 months ago

          That’s fine, but why?

          • refalo@programming.dev
            link
            fedilink
            arrow-up
            6
            arrow-down
            1
            ·
            edit-2
            11 months ago

            It is a privacy and GDPR nightmare, basically all federated services right now are.

            https://github.com/libremonde-org/paper-research-privacy-matrix.org/blob/master/part1/README.md

            https://web.archive.org/web/20240611200030/https://hackea.org/notas/matrix.html

            https://anarc.at/blog/2022-06-17-matrix-notes/

            https://web.archive.org/web/20210804205638/https://serpentsec.1337.cx/matrix

            • uis@lemm.ee
              link
              fedilink
              arrow-up
              1
              ·
              11 months ago

              Looked into anarc blog. What there wss said about Matrix can be said about SMTP and probably XMPP. To do GDPR you need to know every server you have sent message to. And compared to IRC defaults(forward and remove) anything will look like GDPR nightmare. GDPR was not designed for federated(like matrix and activitypub) communications and especially wasn’t designed for peer-to-peer communications.

            • ruse8145@lemmy.sdf.org
              link
              fedilink
              arrow-up
              1
              ·
              11 months ago

              Interesting, thanks for the links I’ll take a look

      • uis@lemm.ee
        link
        fedilink
        arrow-up
        1
        ·
        11 months ago

        bonus points with a personal server

        Only with appservices. Doesn’t make sense otherwise.

    • refalo@programming.dev
      link
      fedilink
      arrow-up
      4
      arrow-down
      2
      ·
      edit-2
      11 months ago

      (for Android) https://molly.im/

      • ivn@jlai.lu
        link
        fedilink
        arrow-up
        1
        ·
        11 months ago

        I can find the desktop client, am I missing something?

        • refalo@programming.dev
          link
          fedilink
          arrow-up
          3
          ·
          edit-2
          11 months ago

          You’re right, there isn’t one, my apologies; I edited the comment.

          You could use some kind of encrypted container on the desktop though, or maybe run it as a separate user that has an encrypted home folder. The problem is you need to define a threat model first. Depending on what you’re afraid of, any particular “solution” could either be way overkill, or never enough.

Privacy@lemmy.ml

privacy@lemmy.ml

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !privacy@lemmy.ml

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
  • Don’t promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

  • Lemmy.ml libre_culture
  • Lemmy.ml privatelife
  • Lemmy.ml DeGoogle
  • Lemmy.ca privacy

Chat rooms

  • [Matrix/Element]Dead

  • Discord

much thanks to @gary_host_laptop for the logo design :)

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 6 users / day
  • 157 users / week
  • 258 users / month
  • 271 users / 6 months
  • 1 local subscriber
  • 31.7K subscribers
  • 2.4K Posts
  • 52K Comments
  • Modlog
  • mods:
  • k_o_t@lemmy.ml
  • tmpod@lemmy.pt
  • Yayannick@lemmy.ml
  • BE: 0.19.11
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org