/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Signal plans to roll out a beta version of its desktop apps that tightens the security of how it stores plain text encryption keys, after downplaying the issue

Signal is finally tightening its desktop client's security by changing how it stores plain text encryption keys for the data store after downplaying the issue since 2018.

BleepingComputer Lawrence Abrams

Context & Ripple Effects

Signal’s privacy posture has long extended beyond message transport: its desktop client followed mobile support, and it later added verification tools across platforms, including safety numbers and QR-code verification.

The new beta addresses a local-client weakness rather than Signal’s core encryption protocol. That distinction matters after earlier debate over data retained for account recovery, which showed how storage choices can become trust issues for a privacy-focused service.

First-order effects

  • Desktop beta users will receive stronger handling of data-store encryption keys, reducing exposure created by storing those keys as plain text.
  • Signal must update and validate its desktop security model after having minimized the concern for years, putting renewed attention on its client-side threat protections.

Second-order effects

  • Security-conscious users and reviewers are likely to assess Signal’s desktop app separately from its end-to-end-encryption claims, with local key protection becoming a concrete criterion.
  • Other encrypted messaging providers face added pressure to scrutinize how desktop clients protect keys and locally stored message data, not only how they encrypt data in transit.

Third-order effects

  • If this pattern persists, encrypted messaging will be judged increasingly on endpoint security and recovery/storage design as well as protocol-level end-to-end encryption.
  • The episode underscores a durable trade-off for privacy products: features and cross-device access expand the local data footprint that must be secured without weakening user trust.

The trend: End-to-end encrypted services are moving from protocol-centric security claims toward deeper scrutiny of how every client device stores, recovers, and exposes sensitive data.

Discussion

  • @mysk_co @mysk_co on x
    TL;DR: Don't install @signalapp for macOS, it is not secure. I carried out this small experiment: - I wrote a simple Python script that copies the directory of Signal's local storage to another location (to mimic a malicious script or app) - I ran the script in the Terminal and […
  • @mer__edith Meredith Whittaker on x
    There's been some chatter about Signal desktop recently, so let's clear the air. Three points: 1. The reported issues rely on an attacker already having *full access to your device* — either physically, through a malware compromise, or via a malicious application running on the
  • @mysk_co @mysk_co on x
    This is the folder structure of Signal's local data on macOS. The encrypted database and encryption key are stored next to each other. The folder is accessible to any app running on the Mac. How could such a blunder be approved by an open-source project reviewed by many experts? …
  • @erratarob Robert Graham on x
    Signal App is beloved by techies like me, but this is just destroying their reputation. You don't attack security researchers. You don't attack security researchers. You don't attack security researchers. Not even when you are absolutely certain they deserve it.
  • @0xcharlie Charlie Miller on x
    On the one hand Signal had some bad bugs that are now fixed. On the other hand when a bad guy is running code on your computer, your messenger apps are not going to be able to protect your comms.
  • @kaepora Nadim Kobeissi on x
    1a) Attacker doesn't need full access, any app running under the same user is fine. 1b) That's not even the issue. The issue is that Signal won't detect silently duplicated Signal Desktop states masquerading as one another and will treat them as one device. 2) It would be nice
  • @profwoodward Alan Woodward on x
    IMHO this is not a bug discovered in @Signal. What people are highlighting is that PCs are not the same as phones. In a PC an authorised user can access just about all parts of the file store. I think there may be some confusion about how sandboxing protects in each.
  • @bleepincomputer @bleepincomputer on x
    At the time, a Signal employee stated in a reply to a forum post about our story: “The core premise of the article is completely mistaken. The database key was never intended to be a secret.”
  • @mysk_co @mysk_co on x
    Signal's message is clear: end-to-end encryption is only about protecting the transmission of chat messages, not protecting the local chat history stored on device. This message is toxic and has a huge impact on our #privacy. @UKZak explains that very well: [image]