signalapp / Signal-Android

A private messenger for Android.
https://signal.org
GNU Affero General Public License v3.0
25.72k stars 6.17k forks source link

Introduce Threat model #782

Closed kmindi closed 6 years ago

kmindi commented 10 years ago

It would be good to know what attacks/threats were already considered in the current design and how they should be prevented. Additionally it would make sense to add those which were left out or are not considered at the moment.

Maybe this could be done in the context of a wiki page.

Threat related Issues

Uncategorized

lorenzhs commented 10 years ago

There have been a few blog posts on this topic. https://whispersystems.org/blog/advanced-ratcheting/ https://whispersystems.org/blog/asynchronous-security/ https://whispersystems.org/blog/simplifying-otr-deniability/

generalmanager commented 10 years ago

@kmindi Sorry for bothering you again, but I'd love to see https://github.com/WhisperSystems/TextSecure/issues/2114 mentioned here. Thanks for your effort!

Quantum-cross commented 9 years ago

I would argue that "#2761 Make disabling passphrase password protected" should be extended. Maybe an option that will immediately lock storage upon entering privacy settings, requiring the passphrase to change anything in the privacy settings and unlock the store again.

kmindi commented 9 years ago

@robcross that comment should go in #2761

automated-signal commented 6 years ago

GitHub Issue Cleanup: See #7598 for more information.