Yesterday, new vulnerability in Signal Messenger was found by mysk_co developer.
What's are the Problems?
Problem 1
Messages are kept in an encrypted file,
however local encryption key is stored in plain text in a file called config.json.
The file is saved in a location accessible to any app, which makes the encryption ineffective.
This is a recognized issue that has been known about for a long time.
Problem 2
Media attachments, such as photos sent and received, are stored locally without encryption.
What's next?
I would recommend unlinking any desktop device from your signal account.
The problems do not apply only to MacOS, but also other desktop platforms.
I would say it's still safe to say the mobile app, if you have already onboarded your family on it.
However, if the transition for you won't be painful, I would go with different options like Threema or SimpleX.
Until next time.
Be Sovererign.
Not only Online.
Marconius Solidus