• Ulrich
      link
      fedilink
      English
      112 months ago

      Copies of messages are also known as archives.

      • tehsYs
        link
        fedilink
        English
        542 months ago

        Signal does not archive messages on server side

        • Ulrich
          link
          fedilink
          English
          10
          edit-2
          2 months ago

          They weren’t talking about the server:

          This app…works in almost exactly the same way as Signal, except that it also archives copies of all the messages passing through it, shattering all of its security guarantees.

          • @[email protected]
            link
            fedilink
            English
            532 months ago

            Later in the article, it talks specifically about the server-side archives being stored in plain text. That’s why the hacker was able to access messages. This isn’t about the local copies on phones.

            • Ulrich
              link
              fedilink
              English
              22 months ago

              Yeah I didn’t read past the misinformation

                • Ulrich
                  link
                  fedilink
                  English
                  2
                  edit-2
                  2 months ago

                  You’re confused, I am not the author of this article. I did not write the statement above, just copied and pasted it here.

                  • @[email protected]
                    link
                    fedilink
                    English
                    222 months ago

                    I’m not confused, you’re intentionally misreading what’s happening for some reason.

                    “Passing through it” pretty clearly refers to the server as that’s what was hacked into and had plain text archives.

                    You’re hyper fixating on the fact that the article says “the app” when referring to both the phone and server pieces to try and argue… something.

              • @[email protected]
                link
                fedilink
                English
                202 months ago

                Maybe you should start reading up on stuff you don’t know about before adding nonsense to internet threads.

                • Ulrich
                  link
                  fedilink
                  English
                  3
                  edit-2
                  2 months ago

                  Don’t know what you mean. I didn’t add any “nonsense”. Just a direct quote from the article in question.

                • NekuSoul
                  link
                  fedilink
                  English
                  122 months ago

                  This is now the third post in the last 24 hours where I stumble into a needlessly long thread because this user is completely obtuse and can’t handle being wrong or a different opinion.

            • @[email protected]
              link
              fedilink
              English
              12 months ago

              That doesn’t really do anything. Attackers need local access to the device to get the database itself. Chances are, they’ll get the key right with it.

              • @[email protected]
                link
                fedilink
                English
                72 months ago

                Molly encrypts it using a passphrase instead of a locally stored key for exactly that reason.

                • @[email protected]
                  link
                  fedilink
                  English
                  12 months ago

                  The passphrase or the unencrypted database are still open in memory. Though that is, of course, a more complicated attack but they could simply read it through the app itself.

                  • @[email protected]
                    link
                    fedilink
                    English
                    22 months ago

                    You can set it to wipe them from memory on different conditions, including instantly if youre that paranoid, sure its still possible. Its an optional feature most people wont use, but its pretty well thought out.