Live data from Hacker News

Another flaw in Signal desktop app leaks chats in plaintext

thehackernews.com

31–40 of 232 posts

Re: Another flaw in Signal desktop app leaks chats in plaintext

#31
post #24

Honestly, and none of you are going to like hearing this, and the Signal people aren't going to appreciate me saying it: if you're serious about messaging securely, don't use Signal Desktop; don't use desktop secure messengers at all. Desktop applications are incredibly risky, far more so than iOS mobile apps are.

I was always uncomfortable about signal on non-iOS devices. I feel the same about password managers too, it’s a giant PITA but I specifically do not want all my passwords in one place if that places is a wild desktop.

Re: Another flaw in Signal desktop app leaks chats in plaintext

#32
post #24

Honestly, and none of you are going to like hearing this, and the Signal people aren't going to appreciate me saying it: if you're serious about messaging securely, don't use Signal Desktop; don't use desktop secure messengers at all. Desktop applications are incredibly risky, far more so than iOS mobile apps are.

Desktop applications are incredibly risky, yes; as for iOS mobile apps we can't even know, as these devices don't allow auditing what software is running on them.

PGP has many problems and I hope a better replacement will come along, but the first step of secure messaging can't be using devices with closed, unauditable software...

Re: Another flaw in Signal desktop app leaks chats in plaintext

#33
post #21
post #14

Earlier quoted context omitted.

The PGP vulnerability is actually in e-mail clients, and it affects almost nobody. And how often do PGP vulnerabilities happen? Signal got two vulnerabilities that affect everyone JUST THIS WEEK .

By "almost nobody", you mean everyone who used Apple Mail/GPGTools and Thunderbird/Enigma, meaning, the vast majority of everybody who used PGP?

Are GPGMail and Enigmail really more popular than other extensions/clients? genuinely asking since I am not aware of any study on PGP usage.

Re: Another flaw in Signal desktop app leaks chats in plaintext

#34
post #22
post #21

Earlier quoted context omitted.

By "almost nobody", you mean everyone who used Apple Mail/GPGTools and Thunderbird/Enigma, meaning, the vast majority of everybody who used PGP?

Thunderbird does not download remote content by default. I don't know anybody who is using Apple Mail with GPG, but if there are such people, they have been doing it very wrong regardless of this vulnerability. It's an unsafe combination. I have no statistics on what people use PGP with, but asserting that most people use it with Apple Mail and Thunderbird is baseless and without proof.

> Thunderbird does not download remote content by default.

The researchers behind EFAIL found a number of ways to bypass the remote content setting. Not only that, but Hanno Böck found another one today[1] that hasn't been fixed yet.

[1]: https://twitter.com/hanno/status/997138771194859521

Re: Another flaw in Signal desktop app leaks chats in plaintext

#35
post #28
post #24

Honestly, and none of you are going to like hearing this, and the Signal people aren't going to appreciate me saying it: if you're serious about messaging securely, don't use Signal Desktop; don't use desktop secure messengers at all. Desktop applications are incredibly risky, far more so than iOS mobile apps are.

And we're back at "really good security is to inconvenient to use" :/

To be fair, Apple has done a great job at making a device that does both without much compromise.

Re: Another flaw in Signal desktop app leaks chats in plaintext

#36
post #29
post #28

Earlier quoted context omitted.

And we're back at "really good security is to inconvenient to use" :/

This is a rare case where things are inconvenient for nerds to use, but more convenient for ordinary people, who tend to be more comfortable doing stuff on mobile platforms than nerds are.

[deleted]

Re: Another flaw in Signal desktop app leaks chats in plaintext

#37
post #15

Earlier quoted context omitted.

Can you provide some examples?

OpenSSL? Remember Heartbleed?

I believe parent was asking for secure software written in JS. I'm curious, too. (And examples of insecure software written in C suprise no one, do they?)

Re: Another flaw in Signal desktop app leaks chats in plaintext

#38
post #24

Honestly, and none of you are going to like hearing this, and the Signal people aren't going to appreciate me saying it: if you're serious about messaging securely, don't use Signal Desktop; don't use desktop secure messengers at all. Desktop applications are incredibly risky, far more so than iOS mobile apps are.

Care to explain? I mean, in principle. I distrust Signal Desktop, whether it's built on Chrome or on Electron, because either of those "platforms" are more complex than my OS (Debian GNU/Linux). But you seem to be making a more general point... what's the reasoning?

Re: Another flaw in Signal desktop app leaks chats in plaintext

#39
post #32
post #24

Honestly, and none of you are going to like hearing this, and the Signal people aren't going to appreciate me saying it: if you're serious about messaging securely, don't use Signal Desktop; don't use desktop secure messengers at all. Desktop applications are incredibly risky, far more so than iOS mobile apps are.

Desktop applications are incredibly risky, yes; as for iOS mobile apps we can't even know, as these devices don't allow auditing what software is running on them. PGP has many problems and I hope a better replacement will come along, but the first step of secure messaging can't be using devices with closed, unauditable software...

They down-vote you, but you are 100% right. Using a mobile phone is intrinsically more insecure because they can track you much more easily, and you have much less control over the OS.

Re: Another flaw in Signal desktop app leaks chats in plaintext

#40
post #24

Honestly, and none of you are going to like hearing this, and the Signal people aren't going to appreciate me saying it: if you're serious about messaging securely, don't use Signal Desktop; don't use desktop secure messengers at all. Desktop applications are incredibly risky, far more so than iOS mobile apps are.

This may or may not be true, but in a lot of cases where you need encryption, you also need not to have a GPS tracker on you while you're using it. You have (at least slightly) more chance of being anonymous with a dedicated laptop computer than you have with any smartphone.
Post reply on HN