Decrypting the Signal App
cellebrite.com
Decrypting the Signal App
1–10 of 24 posts
Re: Decrypting the Signal App
#2Re: Decrypting the Signal App
#3This is not newsworthy, there are normal tools that do similar things: https://github.com/xeals/signal-back
Ugh.
Re: Decrypting the Signal App
#4Re: Decrypting the Signal App
#5This sounded like just the process you’d use once you have the key, but getting the key is presumably the hardest part.
So, is Signal Secure?
Re: Decrypting the Signal App
#6Re: Decrypting the Signal App
#7> Decrypting messages and attachments sent with Signal has been all but impossible…until now.
> We found that acquiring the key requires reading a value from the shared preferences file and decrypting it using a key called “AndroidSecretKey”, which is saved by an android feature called “Keystore”.
Yeah, if you have all the keys you can decrypt stuff..
This is dumb, pleas please do not upvote
Re: Decrypting the Signal App
#8Re: Decrypting the Signal App
#9The much more interesting question is how they might extract keys from the Android Keystore (where key material is very often stored in a Secure Element or similar), but they don't even mention that this might be quite challenging - the article just ignores the question.
Re: Decrypting the Signal App
#10How do they get the key? This sounded like just the process you’d use once you have the key, but getting the key is presumably the hardest part. So, is Signal Secure?