this post was submitted on 06 Jul 2024
373 points (91.0% liked)

Technology

59207 readers
2934 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] Zak@lemmy.world 174 points 4 months ago (4 children)

Signal should change this, but it's typical of the traditional desktop OS security model in which applications running under the user's account are considered trustworthy. Security-oriented software like Signal should take a more hardened approach, but this is not some glaring security hole.

[–] cestvrai@lemm.ee 59 points 4 months ago

That’s what I was thinking, my private keys are also chilling in plaintext on my filesystem.

[–] NobodyElse@sh.itjust.works 36 points 4 months ago (1 children)

With even email clients and web browsers running arbitrary and untrusted remote code on a regular basis, that model needs serious reconsideration.

This xkcd shouldn’t still be insightful. https://xkcd.com/1200/

[–] ChillPill@lemmy.world 11 points 4 months ago (3 children)

Maybe its time to rethink desktop security. I realize that there is credential manager on windows, keychain on mac, and similar on gnu/linux; even with that it seems for a lot of services "all" you need to do is steal a cookie and all of a sudden you are someone else.

[–] MeanEYE@lemmy.world 2 points 4 months ago

Idea of using a web browser for a platform was dumb enough and the reason why none of the keys were stored in appropriate services.

[–] jdeath@lemm.ee 1 points 4 months ago

seems to be the way both apple and MS are going.

[–] vrighter@discuss.tchncs.de -2 points 4 months ago (1 children)

fuck no. It's imbossible to be productive on an android or ios phone, where the os is hostile to you actually using it the way you want.

For an example of rethinking desktop security, see wayland in linux, and how ll accessibility programs now ~~don't~~ cannot possibly work.

[–] mrvictory1@lemmy.world 0 points 4 months ago (1 children)

DeX mode: Am I a joke to you?

[–] vrighter@discuss.tchncs.de 5 points 4 months ago

i do have and use that. But it's still running android apps. which are designed for a touchscreen.

Termux is great though

[–] kerrigan778@lemmy.world 8 points 4 months ago (1 children)

I mean if somebody has physical access and is logged in they have your data anyways right?

[–] MeanEYE@lemmy.world 2 points 4 months ago

For Linux not much of a problem since amount of malware is not that big. On Windows however a different story.