Nemeski@lemm.ee to Privacy Guides@lemmy.oneEnglish · 4 months agoSignal under fire for storing encryption keys in plaintextstackdiary.comexternal-linkmessage-square43fedilinkarrow-up1212arrow-down11cross-posted to: [email protected][email protected][email protected][email protected][email protected][email protected]
arrow-up1211arrow-down1external-linkSignal under fire for storing encryption keys in plaintextstackdiary.comNemeski@lemm.ee to Privacy Guides@lemmy.oneEnglish · 4 months agomessage-square43fedilinkcross-posted to: [email protected][email protected][email protected][email protected][email protected][email protected]
minus-squareTramort@programming.devlinkfedilinkEnglisharrow-up45arrow-down1·4 months agoIt is a super important detail, but it’s still unforgivable for an app that expects privacy to be part of its brand identity.
minus-squarebreadsmasher@lemmy.worldlinkfedilinkEnglisharrow-up8·4 months ago unforgivable yeah absolutely agreed
minus-squarebrakebreaker101@lemmy.worldlinkfedilinkEnglisharrow-up3·4 months agoThis is a big difference between privacy and security.
minus-squareTramort@programming.devlinkfedilinkEnglisharrow-up3·4 months agoAgreed But you can’t have privacy without security, and any privacy brand must have security in their bones.
minus-squareclaudiop@lemmy.worldlinkfedilinkEnglisharrow-up7·4 months agoYou can’t encrypt anything without a key. This is the key. If it wasn’t in plaintext then it would be encrypted. Then you’d need a key for that. Where do you put it? Phone OSs have mechanisms to solve this. Desktop ones do not.
It is a super important detail, but it’s still unforgivable for an app that expects privacy to be part of its brand identity.
yeah absolutely agreed
This is a big difference between privacy and security.
Agreed
But you can’t have privacy without security, and any privacy brand must have security in their bones.
You can’t encrypt anything without a key. This is the key. If it wasn’t in plaintext then it would be encrypted. Then you’d need a key for that. Where do you put it?
Phone OSs have mechanisms to solve this. Desktop ones do not.