https://twitter.com/nathanielrsuchy/status/1054720111330951168
- nathanielrsuchy
Explaining further about how it works, Bleeping Computer stated,
“When Signal Desktop is installed, it will create an encrypted SQLite database called db.sqlite, which is used to store the user's messages. The encryption key for this database is automatically generated by the program when it is installed without any interaction by the user. As the encryption key will be required each time Signal Desktop opens the database, it will store it in plain text to a local file called %AppData%\Signal\config.json on PCs and on a Mac at ~/Library/Application Support/Signal/config.json.”And that’s what makes the function a vulnerability. Anyone having physical access to the computer can open the plain text file to find the decryption key. The attacker may then use this key to open up the SQLite database. Hence, he can easily access the entire app contents.
“They stopped responding to my beta feedback emails a while ago,”said Suchy while replying to his tweet.
What’s more alarming here is that the service has yet to patch the bug. It means, for now, all Signal users need to be extra cautious while using Signal Desktop app, as it risks their privacy.
Take your time to comment on this article.