Signal Working to Close a Security Vulnerability in Its Desktop App

Telegram is fixing a flaw in the security of its desktop app that has lingered for years. As reported by BleepingComputer, Signal’s Desktop app on both Windows and Mac creates an SQLite database when it’s first installed. The program generates a key for that database’s encryption which is then stored as a plain text file locally on the machine. Anyone with access to the machine can get into that file.

Not great.

Signal is an encrypted chat application with a good reputation. For many, it’s their daily driver communication platform. Its end-to-end encryption system is so good it’s used in other programs like WhatsApp. On mobile, it’s fantastic. On desktop computers? Less so.

What’s bizarre is that this vulnerability in Signal’s desktop app has been around for years. BleepingComputer first reported on it in 2018. At the time, Signal told users on its forums that the database key was never meant to be kept secret.

“The reported issues rely on an attacker already having *full access to your device* — either physically, through a malware compromise, or via a malicious application running on the same device. This is not something that Signal, or any other app, can fully protect against. Nor do we ever claim to,” Signal President Meredith Whitaker said in a post on X on July 9.

So why is all of this resurfacing now? Elon Musk, right-wing culture war politics, and Telegram.

Telegram is another popular messaging app, especially in Europe, Russia, and the Middle East. It doesn’t, by default, have end-to-end encryption. It’s also a vector for malware, scams, and violent imagery. On May 8, its CEO Pavel Durov called out Signal as an agent of the U.S. government in a post on Telegram.

“The US government spent $3 million to build Signal’s encryption, and today the exact same encryption is implemented in WhatsApp, Facebook Messenger, Google Messages and even Skype,” Durov said. “It looks almost as if big tech in the US is not allowed to build its own encryption protocols that would be independent of government interference.”

Durov was reacting to a report from right-wing provocateur Chris Ruffo, who called out Signal for its involvement with NPR CEO Katherine Maher. “There are known vulnerabilities with Signal that are not being addressed,” Musk said on X in response to Ruffo’s report.

No communication platform is secure, but there are gradients. “Signal Protocol, the cryptography behind Signal (also used in WhatsApp and several other messengers) is open source and has been intensively reviewed by cryptographers. When it comes to cryptography, this is pretty much the gold standard,” Johns Hopkins security researcher Matthew Green said on X at the time of the controversy.

According to a Signal engineer on Github, the plan is to use the Electron safeStorage API. This would allow Signal to utilize each OS’s own cryptography systems to add an extra layer of protection for the JSON where the key is stored. “This is a big change that will require a lot of testing,” the Signal engineer said on GitHub. “It will start rolling out soon in an upcoming beta release and hit production shortly after that assuming everything goes well.”

Signal did not return Gizmodo’s request for comment.

Security concerns around our devices are top of mind right now. AT&T just revealed that hackers accessed its database in April and downloaded “nearly all” of its customer’s data from a period between May 2022 and October 2022.

Trending Products

0
Add to compare
Snpurdiri 60% Wired Gaming Keyboard, RGB Backlit Mini Keyboard, Waterproof Small Ultra-Compact 61 Keys Keyboard for PC/Mac Gamer, Typist, Travel, Easy to Carry on Business Trip(Black-White)
0
Add to compare
Original price was: $31.99.Current price is: $27.98.
13%
0
Add to compare
Logitech G413 TKL SE Mechanical Gaming Keyboard – Compact Backlit Keyboard with Tactile Mechanical Switches, Anti-Ghosting, Compatible with Windows, macOS – Black Aluminum
0
Add to compare
Original price was: $69.99.Current price is: $59.99.
14%
0
Add to compare
Loigys Wireless Keyboard, 2.4G Full-Sized Ergonomic Wireless Computer Keyboard with Wrist Rest for Windows, Mac OS…
0
Add to compare
$25.99
0
Add to compare
Logitech MK335 Wireless Keyboard and Mouse Combo – Black/Silver
0
Add to compare
$29.99
0
Add to compare
Computer Keyboard Wired, Plug Play USB , Low Profile Chiclet Keys, Large Number Pad, Caps Indicators, Foldable Stands, Spill-Resistant, Anti-Wear Letters for Windows Mac PC Laptop, Full Size
0
Add to compare
Original price was: $19.99.Current price is: $14.99.
25%
0
Add to compare
KLIM Chroma Wireless Gaming Keyboard RGB – Backlit Wireless Keyboard – Long-Lasting Rechargeable Battery – Quiet Water Resistant Ergonomic Keyboard – Teclado Gamer – PC PS5 PS4 Xbox One Mac – Black
0
Add to compare
Original price was: $49.97.Current price is: $29.97.
40%
0
Add to compare
Redragon S101 Gaming Keyboard, M601 Mouse, RGB Backlit Gaming Keyboard, Programmable Backlit Gaming Mouse, Value Combo Set [New Version]
0
Add to compare
Original price was: $51.99.Current price is: $37.99.
27%
0
Add to compare
Dacoity Gaming Keyboard, 104 Keys All-Metal Panel, Rainbow LED Backlit Quiet Computer Keyboard, Wrist Rest, Multimedia…
0
Add to compare
$29.99
.

We will be happy to hear your thoughts

Leave a reply

Pin It on Pinterest

Share This
Boston Made, Inc.
Logo
Register New Account
Compare items
  • Total (0)
Compare
0
Shopping cart