> We found that acquiring the key requires reading a value from the shared preferences file and decrypting it using a key called “AndroidSecretKey”, which is saved by an android feature called “Keystore”. I'm not familiar with Android, but is this an easy step, or a "draw the rest of the fucking owl" step?
Signal: Firm claims to have cracked chat app's encryption
11–18 of 18 posts
Re: Signal: Firm claims to have cracked chat app's encryption
#12> Once the decrypted key is obtained
there are a few steps missing between these 2 paragraphs!
Re: Signal: Firm claims to have cracked chat app's encryption
#13> Decrypting Signal messages and attachments was not an easy task. It required extensive research on many different fronts to create new capabilities from scratch. At Cellebrite, however, finding new ways to help those who make our world a safer place is what we’re dedicated to doing every day. Nice PR spin and non-story - yes, with access to the Android keystore secret, the database can be decrypted. Doesn't work if…
Re: Signal: Firm claims to have cracked chat app's encryption
#14While potentially worrisome I always figured the biggest benefit of using Signal was the self destructing messages. If you are (as the article states) using Signal as a protester to "communicate securely with their teams marshaling protestors, discussing tactics..." I would definitely enable self destructing messages in short time frame. Also in order to get to the Signal data storage you would first have to defeat t…
Re: Signal: Firm claims to have cracked chat app's encryption
#15> The whole article read like amateur hour, which is I assume why they removed it.
- Moxie
Re: Signal: Firm claims to have cracked chat app's encryption
#16Re: Signal: Firm claims to have cracked chat app's encryption
#17I get that this is a silly threat model, but the sooner we rely on non-mass storage for secrets, the better.
Re: Signal: Firm claims to have cracked chat app's encryption
#18How long until devices start using TPM-type chips to store secrets? I get that this is a silly threat model, but the sooner we rely on non-mass storage for secrets, the better.
Android is much more fragmented ecosystem but most flagship manufacturers offer something similar.