Why can't we have nice things? stackdiary.com/signal-under-fire-for-storing-encryption-keys-in-plaintext/
This is pure incompetence
@zleap @mttaggart that they don't encrypt keys on the desktop isn't. either you can trust a device or you can't. it's trivial to extract the keys in some way by just waiting for them to be unlocked.
what really is a blunder is that they don't do something about multiple concurrent sessions using the same keys.
How is it trivial to get the keys when using an API to store secrets?
https://specifications.freedesktop.org/secret-service/latest/ch01.html
@bonifartius
Signal was supposed to use that API, if you can tell me how:
> it's trivial to extract the keys in some way by just waiting for them to be unlocked.
with that API?
I don't care about your opinion on Dbus.