• asdfasdfasdf@lemmy.world
      link
      fedilink
      English
      arrow-up
      12
      ·
      4 months ago

      A pull request was made in April 2023 to implement Electron’s safeStorage API to address this problem, but there has been no follow-up from Signal

      I hate hearing shit like this. What are they thinking?

      • schizo@forum.uncomfortable.business
        link
        fedilink
        English
        arrow-up
        2
        ·
        4 months ago

        They’re thinking “This doesn’t improve shareholder value, so we’re not going to put it on a sprint this quarter”, same as every other commercial piece of software does.

        Also, this quarter becomes “ever” after about six months of it sitting in a backlog waiting.

    • ilickfrogs@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      ·
      edit-2
      4 months ago

      Researchers were able to clone a user’s entire Signal session by copying the local storage directory, allowing them to access the chat history on a separate device

      This has actually been useful for me in the past when reinstalling my OS lmao. In an ideal world we could reverify by entering a code from our phones to unlock the desktop local storage after moving it. My biggest wish for Signal is more seamless message history movement across devices and ecosystems. Fuck even proper back ups would be nice.

      • NinjaCheetah@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        1
        ·
        4 months ago

        Not having backups here on iOS stresses me out. I like using iOS beta updates, but knowing I’m one bad beta from having to restore my phone (where every other little thing except Signal is backed up and waiting) and lose my conversation history forever really bugs me.

      • EngineerGaming@feddit.nl
        link
        fedilink
        English
        arrow-up
        1
        ·
        4 months ago

        My biggest issue with Signal is it being so mobile-oriented. Mobile use seems to be encouraged, and even to register you are directly told to go to the mobile app (and if you register in a VM, you’re then stuck using it because it wants you to scan a QR code which is so easy to do in a VM!) No thanks, I don’t trust my mobile - they’re much harder to make private and “yours” than a desktop. Was it that hard to just add a field for entering the verification code in the desktop client? Sure, I did end up using signal-cli, but it is not mentioned anywhere officially. Point is about how the Signal itself tries to push you onto mobile.

        • Balder@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          4 months ago

          I don’t trust my mobile - they’re much harder to make private and “yours” than a desktop.

          Still mobile phones are designed with much more security in mind than desktop environments, and basically everybody has a device.

          • EngineerGaming@feddit.nl
            link
            fedilink
            English
            arrow-up
            1
            ·
            4 months ago

            Security is not everything though, you need to balance it with privacy and independence as well. Which are, indeed, harder on Android.