Nemeski@lemm.ee to Privacy Guides@lemmy.oneEnglish · 6 months agoSignal under fire for storing encryption keys in plaintextstackdiary.comexternal-linkmessage-square45fedilinkarrow-up1207arrow-down11cross-posted to: cybersecurity@sh.itjust.worksprivacy@lemmy.worldprivacytechnology@lemmy.worldfoss@beehaw.orgprivacy@lemmy.ca
arrow-up1206arrow-down1external-linkSignal under fire for storing encryption keys in plaintextstackdiary.comNemeski@lemm.ee to Privacy Guides@lemmy.oneEnglish · 6 months agomessage-square45fedilinkcross-posted to: cybersecurity@sh.itjust.worksprivacy@lemmy.worldprivacytechnology@lemmy.worldfoss@beehaw.orgprivacy@lemmy.ca
minus-squareTramort@programming.devlinkfedilinkEnglisharrow-up43·6 months agoIt is a super important detail, but it’s still unforgivable for an app that expects privacy to be part of its brand identity.
minus-squarebreadsmasher@lemmy.worldlinkfedilinkEnglisharrow-up8·6 months ago unforgivable yeah absolutely agreed
minus-squarebrakebreaker101@lemmy.worldlinkfedilinkEnglisharrow-up3·6 months agoThis is a big difference between privacy and security.
minus-squareTramort@programming.devlinkfedilinkEnglisharrow-up3·6 months agoAgreed But you can’t have privacy without security, and any privacy brand must have security in their bones.
minus-squareclaudiop@lemmy.worldlinkfedilinkEnglisharrow-up7·6 months agoYou can’t encrypt anything without a key. This is the key. If it wasn’t in plaintext then it would be encrypted. Then you’d need a key for that. Where do you put it? Phone OSs have mechanisms to solve this. Desktop ones do not.
It is a super important detail, but it’s still unforgivable for an app that expects privacy to be part of its brand identity.
yeah absolutely agreed
This is a big difference between privacy and security.
Agreed
But you can’t have privacy without security, and any privacy brand must have security in their bones.
You can’t encrypt anything without a key. This is the key. If it wasn’t in plaintext then it would be encrypted. Then you’d need a key for that. Where do you put it?
Phone OSs have mechanisms to solve this. Desktop ones do not.