HomeSecuritySignal fixes encryption key flaw

Signal fixes encryption key flaw

Signal is finally beefing up the security of desktop client by changing how it stores plaintext encryption keys after downgrading the issue in 2018.

See also: The EU wants to control users' messages – Signal reacts!

Signal

As reported by BleepingComputer in 2018, when Signal Desktop for Windows or Mac, it creates an encrypted SQLite database to store a user's messages. This database is encrypted using a key generated by the program and without user input.

In order for a program to decrypt an encrypted database and use it to store data, it must have access to the encryption key. In Signal's case, it stores the encryption key as plain text in a local file called %AppData%\Signal\config.json on Windows and ~/Library/Application Support/Signal/config.json on Mac.

However, if Signal can access this key, so can any other user or program running on the computer, rendering the encrypted database useless and providing little to no additional security.

One solution offered by the researcher who found this flaw, Nathaniel Suchy, was to encrypt the local database with a user-supplied password that is never stored anywhere, as we see with cloud backup software, web browsers, password managers, and cryptocurrency wallets.

See also: Signal: Protecting your phone number using usernames

When BleepingComputer contacted Signal about the flaw in 2018, it never received a response.

Signal fixes encryption key flaw

Instead, a manager responded to a user's concerns on the forum, stating that database security was never something it claimed to provide.

“The database key was never intended to be secret. Encryption is not something Signal Desktop is currently trying to provide or has ever claimed to provide,” the Signal employee responded.

To be fair to Signal, encrypting local databases without a user-supplied password is a problem for all apps and relies on extra steps to further strengthen security.

However, as a company that prides itself on security and privacy, it was strange that the organization dismissed the issue and didn't try to provide a solution.

See also: Signal: Tests the use of usernames to protect phone numbers

An encryption key is a string of characters used in encryption algorithms to modify data so that it is unreadable to unauthorized users. The key is necessary for both encrypting and decrypting information, ensuring secure communication and data protection. In modern cryptography, keys can be symmetric or asymmetric. The strength of an encryption relies largely on the length and complexity of the key, which must be kept secret and secure to maintain the integrity of the encrypted data.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS