Join Nostr
2026-04-11 10:08:12 UTC
in reply to

mleku on Nostr: i dumped my whole signal chat history last week and learned that the initialization ...

i dumped my whole signal chat history last week and learned that the initialization vector of the sqlite database encryption is a static series of space characters. i'm not surprised at all that "after uninstalling" it can be found. even if it deleted the files, which i doubt, the data is encrypted with the system keychain, so logging in opens it, the IV is such that it can be subjected to a plaintext cryptanalysis. it's a circus. signal is the absolute worst pick. matrix is the only one, which can only be unlocked by using the export feature in the UI. telegram i'm sure their stuff is bad as welll, maybe not as bad as signal, and simplex, well, completely crappy, written in a terrible programming language, zero cross-device sync, and mobile first.