@metacolon I know I can encrypt my /home even after installing the system, but that would be slow and data could be at risk of being corrupted or erased if it goes wrong, it's just not something I want to do now, I'll do it someday, and I'll go all in. The performance impact isn't that big nowadays, even on hard drives, even with FDE.
As for voicing my criticism - I'm not trying to sound grateful OR ungrateful.
What Signal is doing is nice, they are definitely helping out people in countries where censorship is front and center.
But at the same time, you WOULD expect a project that is literally focused on a secure and private instant messenger, to not ignore a glaring issue that was known since 2016 (or 2018), because it is a big issue nonetheless.
Meredith's statement was thoroughly disappointing, though, considering it's a blatant lie when they say the issue can't be fixed.
@metacolon "The reported issues rely on an attacker already having *full access to your device* — either physically, through a malware compromise, or via a malicious application running on the same device. This is not something that Signal, or any other app, can fully protect against. Nor do we ever claim to."
But Signal can take steps against this happening, by literally encrypting the attachments, this is possible, and we know it is, because many other programs have done it already. It's a basic feature Signal refuse(d)s to implement.
"The posters who raised this issue did so without contacting us directly. Instead, they went straight to social media, in some cases using inflammatory language. And they dropped these claims over a US holiday weekend. This is the opposite of responsible disclosure."
This is in bad faith. The issue was KNOWN for years, it was only brought back to light. Mysk doesn't need to contact Signal to talk about this issue, it's not something new.
@metacolon "The reported issues rely on an attacker already having *full access to your device* — either physically, through a malware compromise, or via a malicious application running on the same device. This is not something that Signal, or any other app, can fully protect against. Nor do we ever claim to."