Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yeah, it's cause of the way their crypto works, you encrypt the next message with the hash of the previous or something of the sort. Somebody stored it in plaintext for the desktop version, and I believe it's a SQLite DB so it was easy to discover... It sucks, I wish they had at least encrypted it with a pin at the minimum or something? Maybe Yubikey might make sense for Signalin the desktop not sure.

Also the messages are stored in plaintext:

https://github.com/signalapp/Signal-Desktop/issues/1017

They say it's a non-fix cause you can use full disk encryption, and honestly that's what I do anyway, so I'm not as bothered.



Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: