HomeSecuritySignal: Desktop application messages are unencrypted

Signal: Desktop app messages are unencrypted

A serious flaw in the process used by the Signal desktop app to encrypt messages stored on local disk leaves them unprotected against hackers.

signal

When you install the Signal desktop app, an encrypted database named “db.sqlite” is created on your computer, which is used to store copies of your messages. The database encryption key is automatically generated by the app and stored without any action on your part.

However, since the encryption key is needed every time something needs to be read from the database, as well as to write new entries, the key is kept locally. But here is where the error is found. The path in which the encryption key is stored is predefined (%AppData%\Signal\config.json) and no type of encoding is used. So, simply by opening the config.json file we have access to the encryption key that unlocks the database with all the messages of our Signal account.

According to Nathaniel Suchy, who made the discovery, this tactic exposes Signal users to all sorts of malware and attackers who can access their personal computer. The moral is that encrypting a database is only good and useful when the decryption key can be safely stored.

The use of user-generated encryption keys is a common tactic, although it is most commonly used in cloud backups, password managers, and cryptocurrency wallets. The downside to this tactic is that there is no way to recover the data if the user loses their key.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS