submitted 1 month ago* (last edited 1 month ago) by to c/linux@lemmy.ml
 

I have a hard time understanding the benefits of the keyring (e.g. GNOME keyring). I get the convenience parts - I don't have to enter password for something every time I want to use it (e.g. mounted encrypted drive) and I don't have to create a secret for some background stuff (applications keys). But the problem is, if I understand it correctly, that every application has the same access to my keyring, so, in theory, a malicious application can just read my Signal key and they can just read all my Signal messages right? Is there a point, then, in encrypting e.g. local database (like Signal) if the key to that database is readily available anyway? Any input is welcome. thanks!

you are viewing a single comment's thread
view the rest of the comments
[–] 1 point 2 weeks ago (1 child)

Long story short: Microsoft just helped pop an alleged hacker using some windows device ID. I linked to a post in the hackernews thread about d-bus:

https://lemmy.world/post/49138921

https://news.ycombinator.com/item?id=48815684

  • source
  • parent
  • hideshow 2 child comments
  • [–] [S] 1 point 2 weeks ago (1 child)

    How is this related to the keyring security issues? (Don't get me wrong, it's interesting news, and I already saw it in the Privacy sublemmy)

  • source
  • parent
  • hideshow 2 child comments