Signal is finally beefing up the security of desktop client by changing how it stores plaintext encryption keys after downgrading the issue in 2018.
See also: The EU wants to control users' messages – Signal reacts!

As reported by BleepingComputer in 2018, when Signal Desktop for Windows or Mac, it creates an encrypted SQLite database to store a user's messages. This database is encrypted using a key generated by the program and without user input.
In order for a program to decrypt an encrypted database and use it to store data, it must have access to the encryption key. In Signal's case, it stores the encryption key as plain text in a local file called %AppData%\Signal\config.json on Windows and ~/Library/Application Support/Signal/config.json on Mac.
However, if Signal can access this key, so can any other user or program running on the computer, rendering the encrypted database useless and providing little to no additional security.
One solution offered by the researcher who found this flaw, Nathaniel Suchy, was to encrypt the local database with a user-supplied password that is never stored anywhere, as we see with cloud backup software, web browsers, password managers, and cryptocurrency wallets.
See also: Signal: Protecting your phone number using usernames
When BleepingComputer contacted Signal about the flaw in 2018, it never received a response.

Instead, a manager responded to a user's concerns on the forum, stating that database security was never something it claimed to provide.
“The database key was never intended to be secret. Encryption is not something Signal Desktop is currently trying to provide or has ever claimed to provide,” the Signal employee responded.
To be fair to Signal, encrypting local databases without a user-supplied password is a problem for all apps and relies on extra steps to further strengthen security.
However, as a company that prides itself on security and privacy, it was strange that the organization dismissed the issue and didn't try to provide a solution.
See also: Signal: Tests the use of usernames to protect phone numbers
An encryption key is a string of characters used in encryption algorithms to modify data so that it is unreadable to unauthorized users. The key is necessary for both encrypting and decrypting information, ensuring secure communication and data protection. In modern cryptography, keys can be symmetric or asymmetric. The strength of an encryption relies largely on the length and complexity of the key, which must be kept secret and secure to maintain the integrity of the encrypted data.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: bleepingcomputer
