5 ms·
There is something which Signal could do to help even in this scenario. Give the user a logout option which leaves nothing but ciphertext on the device (e.g. by
by ianopolous 6y ago
There is something which Signal could do to help even in this scenario. Give the user a logout option which leaves nothing but ciphertext on the device (e.g. by encrypting any plaintext keys with the passphrase). To login again you need a passphrase. Then as long as the user has enough time to click logout they are safe even when the device is out of their hands. Of course, after that, it might be prudent to consider the device compromised, and thus not login again afterwards in case it has been backdoored.
- upofadown 6y agoThe Signal app used to have an option to protect the critical data with a strong passphrase but that option was removed. The developers might of considered that the real threat was a remote access trojan that would just keysniff the passphrase. I guess the Cellebrite thing is a reminder that there are other threats. As it is you are pretty much lost if someone is willing to snatch the phone from your hand while you are looking at cat pictures on the web. Phones really need more than one level of "unlocked".
- ianopolous 6y agoThe real use case for this kind of cryptographic logout is travelling through airports. That is a very common situation.
- mr_toad 6y ago> the real threat was a remote access trojan The real threat for most people is forgetting the password.
- ianopolous 6y agoIndeed, which is why logging out would be optional.
- angry_octet 6y agoSignal can at least have timeouts for requiring re-auth (typically biometric). The isolation concept can indeed apply to more than just functional separation, including separation in time, or in search depth (number of records returned) or by classification. It would be quite simple -- require auth to scan backwards more than an hour. Or 'press and hold to mark message as sensitive|expiring'. And possibly require a passphrase to access those sensitive messages / threads. I've applied these techniques for database systems where NTK (need to know) rules apply, to force queries to be narrowly scoped. Likewise system backups don't all need to be online (or in the tape robot), most restores are from the most recent backup.
- ben7799 6y agoExactly.. it would also be possible to design an app that never persists any messages or other information on the phone.. though at that point the whole thing is just a shell over a website. There were applications that worked that way before mobile phones and the web.