• Zak@lemmy.world
    link
    fedilink
    English
    arrow-up
    111
    arrow-down
    2
    ·
    5 months ago

    Signal should change this, but it’s typical of the traditional desktop OS security model in which applications running under the user’s account are considered trustworthy. Security-oriented software like Signal should take a more hardened approach, but this is not some glaring security hole.

    • cestvrai@lemm.ee
      link
      fedilink
      English
      arrow-up
      35
      arrow-down
      1
      ·
      5 months ago

      That’s what I was thinking, my private keys are also chilling in plaintext on my filesystem.

      • ChillPill@lemmy.world
        link
        fedilink
        English
        arrow-up
        8
        ·
        5 months ago

        Maybe its time to rethink desktop security. I realize that there is credential manager on windows, keychain on mac, and similar on gnu/linux; even with that it seems for a lot of services “all” you need to do is steal a cookie and all of a sudden you are someone else.

        • MeanEYE@lemmy.world
          link
          fedilink
          English
          arrow-up
          4
          arrow-down
          3
          ·
          5 months ago

          Idea of using a web browser for a platform was dumb enough and the reason why none of the keys were stored in appropriate services.

      • cley_faye@lemmy.world
        link
        fedilink
        English
        arrow-up
        8
        ·
        5 months ago

        as Electron has no integration with the rest of the system,

        You pretty much can use Electron to build an application and use native OS-specific features. It only requires thinking about it and a bit of work, but technically isn’t much harder to do than with anything else. And there are some things useful in windows for that, based on user login credentials.

        But ultimately, if the developers didn’t care about doing that, it won’t happen, regardless of them using Electron or writing fully native apps.

      • priapus@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        2
        ·
        5 months ago

        Electron is capable of having just as good integration with the system as native applications. It’s just that a lot of people are not optimizing these cross platform apps to have optimal integration with them. Electron has the safeStorage API that allows you to use kwallet or GNOME Keyring to securely store information. I believe both Discord and Spotify use this on Linux.

        • MeanEYE@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          arrow-down
          1
          ·
          5 months ago

          Electron is capable of having just as good integration with the system as native applications

          It will never have this since it’s incapable of using native widgets and theming, which are far more important than just looks, especially to people with disability. safeStorage is something I didn’t know about, but it seems it wasn’t used. Apart from huge RAM footprint, Electron also wakes CPU a lot which makes it absolute garbage on battery powered systems.

          • Balder@lemmy.world
            link
            fedilink
            English
            arrow-up
            2
            ·
            5 months ago

            It will never have this since it’s incapable of using native widgets and theming

            You can criticize Electron’s performance and memory footprint, but as long as there’s an API to access something, it can access the same features as a native app, it just depends on the company’s willingness to do it. HTML is also one of the best platforms in terms of accessibility.

            The problem though, is that cross-platform apps are optimized for that: sharing the same code among systems, and using specific OS features complicate things, so the tendency is to use the same solution for all of them, even when it isn’t the correct one. Also, they make it possible for developers who don’t know a certain OS well to still build for it, making things potentially worse in the user experience.

          • priapus@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            1
            ·
            5 months ago

            it is true that they do not integrate with widgets and theming, but that’s not exclusive to electron. GTK apps don’t follow system widgets, nor will they follow theming on non-gtk desktops. I do also prefer desktop apps not be written in electron for the performance reasons you mentioned.

      • MeanEYE@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        1
        ·
        5 months ago

        For Linux not much of a problem since amount of malware is not that big. On Windows however a different story.

    • asdfasdfasdf@lemmy.world
      link
      fedilink
      English
      arrow-up
      28
      ·
      5 months ago

      A pull request was made in April 2023 to implement Electron’s safeStorage API to address this problem, but there has been no follow-up from Signal

      I hate hearing shit like this. What are they thinking?

    • ilickfrogs@lemmy.world
      link
      fedilink
      English
      arrow-up
      13
      ·
      edit-2
      5 months ago

      Researchers were able to clone a user’s entire Signal session by copying the local storage directory, allowing them to access the chat history on a separate device

      This has actually been useful for me in the past when reinstalling my OS lmao. In an ideal world we could reverify by entering a code from our phones to unlock the desktop local storage after moving it. My biggest wish for Signal is more seamless message history movement across devices and ecosystems. Fuck even proper back ups would be nice.

      • NinjaCheetah@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        2
        ·
        5 months ago

        Not having backups here on iOS stresses me out. I like using iOS beta updates, but knowing I’m one bad beta from having to restore my phone (where every other little thing except Signal is backed up and waiting) and lose my conversation history forever really bugs me.

  • N00dle@lemmy.world
    link
    fedilink
    English
    arrow-up
    8
    ·
    5 months ago

    Am I missing something? Hasn’t this been known for years now? I think they previously commented on this before.

    • MeanEYE@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      ·
      5 months ago

      It has been known and they can’t really change it. I think it’s only now that people are realizing this is an issue or at least something happened to start the avalanche.

  • Flying Squid@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    arrow-down
    1
    ·
    5 months ago

    I told the guy I buy a certain thing that should be legal in this state from that trusting Signal is a bad idea and he should use some coded language if we were going use it. I do anyway, but I doubt that matters.