Nemeski@lemm.ee to Privacy Guides@lemmy.oneEnglish · vor 2 JahrenSignal under fire for storing encryption keys in plaintextstackdiary.comexternal-linkmessage-square49linkfedilinkarrow-up1161arrow-down10cross-posted to: cybersecurity@sh.itjust.worksprivacy@lemmy.worldfoss@beehaw.orgprivacy@lemmy.ca
arrow-up1161arrow-down1external-linkSignal under fire for storing encryption keys in plaintextstackdiary.comNemeski@lemm.ee to Privacy Guides@lemmy.oneEnglish · vor 2 Jahrenmessage-square49linkfedilinkcross-posted to: cybersecurity@sh.itjust.worksprivacy@lemmy.worldfoss@beehaw.orgprivacy@lemmy.ca
minus-squarepearsaltchocolatebar@discuss.onlinelinkfedilinkEnglisharrow-up66·vor 2 JahrenBut… That’s how encryption keys are stored.
minus-squareEvotech@lemmy.worldlinkfedilinkEnglisharrow-up47·vor 2 JahrenNo your don’t understand, you’re supposed to encrypt the keys. Then you encrypt that key And then that key Until it’s all encrypted /s
minus-squareboredsquirrel (he)@slrpnk.netlinkfedilinkEnglisharrow-up22·vor 2 Jahrenopportunistic TPM integration would be nice. I.e. use the security chip of the device, if one is found. Otherwise use password. OR use a Nitrokey etc, which can act as a secure device to store these keys too. Take that, Windows. You dont need a builtin TPM if you can use a Nitrokey 3 with a secure element, externally.
But… That’s how encryption keys are stored.
No your don’t understand, you’re supposed to encrypt the keys.
Then you encrypt that key
And then that key
Until it’s all encrypted /s
opportunistic TPM integration would be nice.
I.e. use the security chip of the device, if one is found. Otherwise use password.
OR use a Nitrokey etc, which can act as a secure device to store these keys too.
Take that, Windows. You dont need a builtin TPM if you can use a Nitrokey 3 with a secure element, externally.