Nemeski@lemm.ee to Privacy Guides@lemmy.oneEnglish · 2 年前Signal under fire for storing encryption keys in plaintextstackdiary.comexternal-linkmessage-square49linkfedilinkarrow-up1161arrow-down10cross-posted to: cybersecurity@sh.itjust.worksprivacy@lemmy.worldfoss@beehaw.orgprivacy@lemmy.ca
arrow-up1161arrow-down1external-linkSignal under fire for storing encryption keys in plaintextstackdiary.comNemeski@lemm.ee to Privacy Guides@lemmy.oneEnglish · 2 年前message-square49linkfedilinkcross-posted to: cybersecurity@sh.itjust.worksprivacy@lemmy.worldfoss@beehaw.orgprivacy@lemmy.ca
minus-squarepearsaltchocolatebar@discuss.onlinelinkfedilinkEnglisharrow-up66·2 年前But… That’s how encryption keys are stored.
minus-squareEvotech@lemmy.worldlinkfedilinkEnglisharrow-up47·2 年前No your don’t understand, you’re supposed to encrypt the keys. Then you encrypt that key And then that key Until it’s all encrypted /s
minus-squareboredsquirrel (he)@slrpnk.netlinkfedilinkEnglisharrow-up22·2 年前opportunistic TPM integration would be nice. I.e. use the security chip of the device, if one is found. Otherwise use password. OR use a Nitrokey etc, which can act as a secure device to store these keys too. Take that, Windows. You dont need a builtin TPM if you can use a Nitrokey 3 with a secure element, externally.
But… That’s how encryption keys are stored.
No your don’t understand, you’re supposed to encrypt the keys.
Then you encrypt that key
And then that key
Until it’s all encrypted /s
opportunistic TPM integration would be nice.
I.e. use the security chip of the device, if one is found. Otherwise use password.
OR use a Nitrokey etc, which can act as a secure device to store these keys too.
Take that, Windows. You dont need a builtin TPM if you can use a Nitrokey 3 with a secure element, externally.