Comment on Signal downplays encryption key flaw, fixes it after X drama

<- View Parent
eager_eagle@lemmy.world ⁨2⁩ ⁨months⁩ ago

But that’s the thing: I haven’t found anything that indicates it can differentiate a legitimate access from a dubious one; at least not without asking the user to authorize it by providing a password and causing the extra inconvenience.

If the wallet asked the program itself for a secret - to verify the program was legit and not a malicious script - the program would still have the same problem of storing and retrieving that secret securely; which defeats the use of a secret manager.

source
Sort:hotnewtop