• Zak@lemmy.world
    link
    fedilink
    English
    arrow-up
    22
    arrow-down
    1
    ·
    3 months ago

    Signal should change this, but it’s typical of the traditional desktop OS security model in which applications running under the user’s account are considered trustworthy. Security-oriented software like Signal should take a more hardened approach, but this is not some glaring security hole.

      • ChillPill@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 months ago

        Maybe its time to rethink desktop security. I realize that there is credential manager on windows, keychain on mac, and similar on gnu/linux; even with that it seems for a lot of services “all” you need to do is steal a cookie and all of a sudden you are someone else.

        • vrighter@discuss.tchncs.de
          link
          fedilink
          English
          arrow-up
          0
          ·
          2 months ago

          fuck no. It’s imbossible to be productive on an android or ios phone, where the os is hostile to you actually using it the way you want.

          For an example of rethinking desktop security, see wayland in linux, and how ll accessibility programs now don’t cannot possibly work.

        • MeanEYE@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          arrow-down
          1
          ·
          2 months ago

          Idea of using a web browser for a platform was dumb enough and the reason why none of the keys were stored in appropriate services.

    • cestvrai@lemm.ee
      link
      fedilink
      English
      arrow-up
      3
      ·
      3 months ago

      That’s what I was thinking, my private keys are also chilling in plaintext on my filesystem.