Labor is dead.

  • Vanilla_PuddinFudge@infosec.pub
    link
    fedilink
    English
    arrow-up
    3
    arrow-down
    1
    ·
    2 days ago

    Meredith Whittaker, the president of the foundation for widely-used global Signal encrypted messaging app, has said it will shut down the system in Australia if forced to hand over its users’ encrypted data to the country’s political surveillance agency, the Australian Security Intelligence Organisation (ASIO).

    raises hand

    “You have stored data on your users?”

    • Fuse Views@infosec.exchange
      link
      fedilink
      arrow-up
      4
      ·
      edit-2
      2 days ago

      @Vanilla_PuddinFudge

      Yes…
      … but that’s OK.

      Lemme explain…

      A Signal user will commonly have the client app installed on their mobile device.

      They may also have a second client on a laptop that syncs the same data.

      If the user goes on holiday for a week but leaves their laptop behind, it won’t be synced to the laptop.

      On return from holiday, the laptop client uses its decryption keys to retrieve the last week’s worth of messages.

      I *think* Signal can do this (retrieve cached messages from the Signal servers) for up to 14 days.

      That said, the entire Signal cache is encrypted on their servers, and one’s messages are fully E2EE and retrievable only by the user.

      (However, one weakness of Signal is that a desktop or laptop client’s cache is stored unencrypted. To secure these, one needs to use full disk encryption at the OS level or higher.)

      @DarkCloud

    • DarkCloud@lemmy.worldOP
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      1 day ago

      Your chats… It’s a messenger service. You can set your chats to disappear if you like, but they’re stored until you set them to be deleted (if you do take that option at all).

      Plus, they store your user name ect…