Labor is dead.

  • Fuse Views@infosec.exchange
    link
    fedilink
    arrow-up
    4
    ·
    edit-2
    2 days ago

    @Vanilla_PuddinFudge

    Yes…
    … but that’s OK.

    Lemme explain…

    A Signal user will commonly have the client app installed on their mobile device.

    They may also have a second client on a laptop that syncs the same data.

    If the user goes on holiday for a week but leaves their laptop behind, it won’t be synced to the laptop.

    On return from holiday, the laptop client uses its decryption keys to retrieve the last week’s worth of messages.

    I *think* Signal can do this (retrieve cached messages from the Signal servers) for up to 14 days.

    That said, the entire Signal cache is encrypted on their servers, and one’s messages are fully E2EE and retrievable only by the user.

    (However, one weakness of Signal is that a desktop or laptop client’s cache is stored unencrypted. To secure these, one needs to use full disk encryption at the OS level or higher.)

    @DarkCloud