My friend and I were discussing cell phone security and he said that if someone backdoored your phone that they could read all your signal messages. Is this true? I would think that the only way to view signal messages is to literally open up the app and view them.

  • poVoq@lemmy.ml
    link
    fedilink
    arrow-up
    11
    arrow-down
    1
    ·
    edit-2
    3 years ago

    You are both sort of right. Signal’s on device storage is AFAIK only weakly encrypted with your screen-lock password (although you can enable a second weak password in Signal specifically). So if your phone is unlocked and backdoored the attacker can pretty much do what ever they want including reading your Signal messages.

    Edit: to make it more clear… someone with a backdoor can just start a hidden application that does the same as the Signal client and open the on device stored messages with out your knowledge. And it is also quite trivial to install a keylogger to capture all passwords including those inside Signal.