logoalt Hacker News

tadzikpktoday at 6:28 PM2 repliesview on HN

> I'm sad that a lot more people don't know that Signal for Desktop is much, much less secure against adversaries with your laptop

Educate us. What makes it less secure?


Replies

armadyltoday at 7:47 PM

In addition to what the other person who replied said, ignoring that iOS/Android/iPadOS is far more secure than macOS, laptops have significantly less hardware-based protections than Pixel/Samsung/Apple mobile devices do. So really the only way a laptop in this situation would be truly secure from LEO is if its fully powered off when it’s seized.

digiowntoday at 6:55 PM

The key in the desktop version is not always stored in the secure enclave, is my assumption (it definitely supports plaintext storage). Theoretically this makes it possible to extract the key for the message database. Also a different malicious program can read it. But this is moot anyway if the FBI can browse through the chats. This isn't what failed here.

show 1 reply