What is Nostr?
TheGuySwann / Guy Swann
npub1h8n…rpev
2024-07-07 14:17:16

TheGuySwann on Nostr: I wouldn't say the conclusion is so simple as "don't install Signal" because it ...

I wouldn't say the conclusion is so simple as "don't install Signal" because it remains superior to typical alternatives (i mean if you're gonna use text or Telegram instead, just use Signal), BUT this is a very important security consideration.

From Mysk🇨🇦🇩🇪 (npub1exw…8x90)
----------------------------------------------------
"Don't install @SignalApp for macOS, it is not secure.

I carried out this small experiment:

- I wrote a simple Python script that copies the directory of Signal's local storage to another location (to mimic a malicious script or app)
- I ran the script in the Terminal and got a copy of my Signal data on my Mac
- I booted a fresh macOS installation in a virtual machine
- I transferred the copy of Signal's data to the VM and placed it where Signal expects it: ~/Library/Application\ Support/Signal
- I installed Signal and started it
- Signal started and restored my session with all the chat histories 😳
- I exchanged a couple messages with a contact from the VM and it worked 😳
- Then, I started Signal on the Mac
- I got three sessions running in unison: Mac, iPhone, and VM 😳

Messages were either delivered to the Mac or to the VM. The iPhone received all messages. All of the three sessions were live and valid. Signal didn't warn me of the existence of the third session [that I cloned]. Moreover, Signal on the iPhone still shows one linked device. This is particularly dangerous because any malicious script can do the same to seize a session.

Perhaps this flaw is what makes some users think that Signal has a "backdoor" as it is easy for sophisticated attackers to target a victim who's using the Mac app and see their chats. (The same may be also true for the Windows app)

#privacy #security"

------------------------------------------------

"This video shows that
@signalapp
(7.15.0) on macOS stores photos and docs sent through the app locally without encryption. Worse, the files are stored in a location accessible by any app or script. However, text messages are stored locally in an encrypted DB."

Author Public Key
npub1h8nk2346qezka5cpm8jjh3yl5j88pf4ly2ptu7s6uu55wcfqy0wq36rpev