I believe weak/no backup encryption to be the primary attack vector against otherwise well-designed e2ee messengers.
I believe weak/no backup encryption to be the primary attack vector against otherwise well-designed e2ee messengers.
Lack of backups is not a retention/deletion policy. Signal chats can, in fact, have a deletion policy set. Instead it directly ties retention to "how long can I last without losing or erasing my phone", which is not a useful proxy.
Anyone sufficiently motivated to keep messages forever can (a) set up the desktop client and back up its data store or (b) set up signal-cli and save everything that comes out of it.
No backups doesn't defeat this, it just makes life harder for everyone who relies on scrollback. Imagine if email worked this way.
Sure, but defaults matter.
Almost nobody uses these in practice, so I think my point largely still stands.
I'm pretty sure that, given their stance on this issue on iOS, they'd start locally encrypting the message database using a key stored in the Android Keystore system (which won't be backed up or extracted).
https://support.signal.org/hc/en-us/articles/360007059752-Ba...
————
> Where can I find the backup file?
> Your backup folder is listed under Signal Settings profile_avatar.png > Chats > Chat backups > Backup folder. Use the files app or plug your phone into a computer to go to the folder.
> For older versions of Signal, the backup file signal-year-month-date-time.backup can be found at /Internal Storage/Signal/Backups or /sdcard/Signal/Backups
The two options, roughly speaking, are: Force users to store some high-entropy passphrase (which most users will then store somewhere not very secure), or let them pick their own passphrase (which won't be very good). This is what WhatsApp does.
A third one would be to allow a short passphrase and guard that by a server-side HSM or maybe SGX, which Signal seems to be somewhat fond of; I'm glad they're not doing that.
Telegram has that. Just forget to log for 6 months and poof.