logo

Signal downplays encryption key flaw, fixes it after X drama

ID: bbd4662c-d2e7-5486-a496-e98781134435

STIX ID: report--bbd4662c-d2e7-5486-a496-e98781134435

Feed Name: Bleeping Computer

Threat Score
50/100

Date Published: 2024-07-11

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Signal Desktop historically stored the local message-store encryption key in plaintext (config.json), undermining at-rest protection if an attacker or malicious process has local or same-user access; this issue resurfaced on social media and researchers prompted Signal to adopt Electron's safeStorage (using platform keystores) as a mitigation, though platform limits (e.g., DPAPI only protecting cross-user access) mean same-user malware can still access the data until stronger user-supplied protections are implemented.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.