Signal plans to roll out a beta version of its desktop apps that tightens the security of how it stores plain text encryption keys, after downplaying the issue
Signal is finally tightening its desktop client's security by changing how it stores plain text encryption keys for the data store after downplaying the issue since 2018.
BleepingComputerLawrence Abrams
Context & Ripple Effects
Signal’s privacy posture has long extended beyond message transport: its desktop client followed mobile support, and it later added verification tools across platforms, including safety numbers and QR-code verification.
The new beta addresses a local-client weakness rather than Signal’s core encryption protocol. That distinction matters after earlier debate over data retained for account recovery, which showed how storage choices can become trust issues for a privacy-focused service.
First-order effects
Desktop beta users will receive stronger handling of data-store encryption keys, reducing exposure created by storing those keys as plain text.
Signal must update and validate its desktop security model after having minimized the concern for years, putting renewed attention on its client-side threat protections.
Second-order effects
Security-conscious users and reviewers are likely to assess Signal’s desktop app separately from its end-to-end-encryption claims, with local key protection becoming a concrete criterion.
Other encrypted messaging providers face added pressure to scrutinize how desktop clients protect keys and locally stored message data, not only how they encrypt data in transit.
Third-order effects
If this pattern persists, encrypted messaging will be judged increasingly on endpoint security and recovery/storage design as well as protocol-level end-to-end encryption.
The episode underscores a durable trade-off for privacy products: features and cross-device access expand the local data footprint that must be secured without weakening user trust.
The trend: End-to-end encrypted services are moving from protocol-centric security claims toward deeper scrutiny of how every client device stores, recovers, and exposes sensitive data.
TL;DR: Don't install @signalapp for macOS, it is not secure. I carried out this small experiment: - I wrote a simple Python script that copies the directory of Signal's local storage to another location (to mimic a malicious script or app) - I ran the script in the Terminal and […
There's been some chatter about Signal desktop recently, so let's clear the air. Three points: 1. The reported issues rely on an attacker already having *full access to your device* — either physically, through a malware compromise, or via a malicious application running on the
This is the folder structure of Signal's local data on macOS. The encrypted database and encryption key are stored next to each other. The folder is accessible to any app running on the Mac. How could such a blunder be approved by an open-source project reviewed by many experts? …
Signal App is beloved by techies like me, but this is just destroying their reputation. You don't attack security researchers. You don't attack security researchers. You don't attack security researchers. Not even when you are absolutely certain they deserve it.
On the one hand Signal had some bad bugs that are now fixed. On the other hand when a bad guy is running code on your computer, your messenger apps are not going to be able to protect your comms.
1a) Attacker doesn't need full access, any app running under the same user is fine. 1b) That's not even the issue. The issue is that Signal won't detect silently duplicated Signal Desktop states masquerading as one another and will treat them as one device. 2) It would be nice
IMHO this is not a bug discovered in @Signal. What people are highlighting is that PCs are not the same as phones. In a PC an authorised user can access just about all parts of the file store. I think there may be some confusion about how sandboxing protects in each.
At the time, a Signal employee stated in a reply to a forum post about our story: “The core premise of the article is completely mistaken. The database key was never intended to be a secret.”
Signal's message is clear: end-to-end encryption is only about protecting the transmission of chat messages, not protecting the local chat history stored on device. This message is toxic and has a huge impact on our #privacy. @UKZak explains that very well: [image]