NewsBytes
    Hindi Tamil Telugu
    More
    In the news
    Narendra Modi
    Amit Shah
    Box Office Collection
    Bharatiya Janata Party (BJP)
    OTT releases
    Hindi Tamil Telugu
    NewsBytes
    User Placeholder

    Hi,

    Logout


    India Business World Politics Sports Technology Entertainment Auto Lifestyle Inspirational Career Bengaluru Delhi Mumbai Visual Stories Find Cricket Statistics Phones Reviews Fitness Bands Reviews Speakers Reviews

    Download Android App

    Follow us on
    • Facebook
    • Twitter
    • Linkedin
     
    Home / News / Technology News / Signal users rejoice! Desktop app gets long-awaited security fix
    In short
    Simplifying... Inshort
    • Signal's desktop app has finally addressed a long-standing security flaw where the encryption key was stored in plain text, making it accessible to anyone using the computer.
    • Despite criticism for not addressing this issue sooner, Signal has now implemented Electron's safeStorage support, a solution proposed by developer Tom Plant, to better secure data from offline attacks.
    • However, the company maintains that if an attacker gains full access to a device, complete data protection cannot be guaranteed.
    Was a long read? Making it simpler...
    Next Article
    Next Article
    Signal users rejoice! Desktop app gets long-awaited security fix
    The issue was first reported in 2018

    Signal users rejoice! Desktop app gets long-awaited security fix

    By Dwaipayan Roy
    Jul 12, 2024
    11:57 am
    What's the story

    Signal, a privacy-centric messaging app, has announced plans to bolster the security of its desktop client, by modifying how it stores plain text encryption keys for data storage. The decision comes in response to public criticism and follows years of downplaying the issue since it was first reported in 2018. The company's desktop version for Windows or Mac uses an encrypted SQLite database to store user messages, which are encrypted via a key generated by the program without user input.

    Flaw

    Encryption key vulnerability sparks concern

    The encryption key, stored as plain text in a local file, is accessible to any user/program running on the computer. This accessibility compromises the security of the encrypted database. Nathaniel Suchy, who discovered this flaw, proposed encrypting the local database with a password supplied by the user that is never stored anywhere. This method mirrors practices used by web browsers, cloud backup software, password managers, and cryptocurrency wallets.

    Company response

    Response to encryption key flaw criticized

    Despite being alerted about this flaw in 2018, Signal did not respond. A Signal Support Manager later addressed a user's concerns on their forum, stating, "The database key was never intended to be a secret. At-rest encryption is not something that Signal Desktop is currently trying to provide or has ever claimed to provide." In 2024, Elon Musk tweeted about known vulnerabilities with Signal that were not being addressed, without specifying what these vulnerabilities were.

    Warning

    Signal's security weakness highlighted by mobile security researchers

    Last week, mobile security researchers Talal Haj Bakry and Tommy Mysk, warned against using Signal Desktop due to its security weakness. They pointed out that photos and apps sent via the app are not stored securely, and that the encryption key for the message store, is still kept in plain text on the system. In response, Signal President Meredith Whittaker downplayed the flaw, claiming that if an attacker gains full access to a device, Signal cannot fully protect the data.

    Security upgrade

    Signal implements support for Electron's safeStorage

    In April, developer Tom Plant proposed a solution to secure Signal's data store from offline attacks, using Electron's safeStorage API. This API provides extra methods to secure the encryption key utilized to encrypt data stored locally on a device. However, this solution was not fully effective for Windows, as it only secures encryption key against other users on the same device. Last week, Signal announced that it had implemented Electron's safeStorage support, which would be offered in a beta update.

    Facebook
    Whatsapp
    Twitter
    Linkedin
    Related News
    Latest
    Signal
    Elon Musk

    Latest

    Olympics: Decoding India's medal haul in badminton Olympics
    Anant Ambani, Radhika Merchant's wedding: Rituals of Gujarati nuptials Antilia
    'RC16' gets bigger as Shiva Rajkumar joins Ram Charan-led film Janhvi Kapoor
    Nepal landslide: 6 Indians missing after buses fall in river Kathmandu

    Signal

    FTC accuses Amazon executives of using Signal to destroy evidence Amazon
    WhatsApp to block screenshots of profile pictures Telegram
    WhatsApp to allow sending messages to Signal, Telegram users soon WhatsApp
    Signal's new feature helps users keep phone numbers private Latest Tech News

    Elon Musk

    X to sue certain boycotting advertisers following damning Congressional hearingĀ  X
    Neuralink ready for 2nd brain chip implantation next week Neuralink
    X backtracks on encryption? Manual review of DMs sparks concerns X
    Investigation exposes environmental damage from Elon Musk's Starship rocket testing Federal Aviation Administration
    Next Article

    Live

    Indian Premier League (IPL) Celebrity Hollywood Bollywood UEFA Champions League Tennis Football Smartphones Cryptocurrency Upcoming Movies Premier League Cricket News Latest automobiles Latest Cars Upcoming Cars Latest Bikes Upcoming Tablets
    About Us Privacy Policy Terms & Conditions Contact Us Ethical Conduct Grievance Redressal News News Archive Topics Archive Download DevBytes Find Cricket Statistics
    Follow us on
    Facebook Twitter Linkedin
    All rights reserved © NewsBytes 2024
    filled star
    half filled star