r/signal 2d ago

Help Security of application lock

Hi all,

How protected is the Signal app when using the app lock feature (that locks it behind biometrics/PIN) in a situation where your phone is stolen while it's unlocked? My understanding is that the database isn't seperately encrypted like Molly's, so would it be possible for someone to extract your messages? If that's the case, is there anything more to do to secure it than using Molly?

Thanks.

5 Upvotes

25 comments sorted by

2

u/Chongulator Volunteer Mod 2d ago

The meaningful protection is using a strong passcode on your phone and locking the entire device, not just one app.

2

u/ephemeralmiko 2d ago

So there isn't any meaningful protection if someone steals your unlocked phone while Signal is still seperately locked?

3

u/3_Seagrass Verified Donor 2d ago

Signal is one tool in your security kit. If someone has your unlocked phone they can already do so much damage, regardless of whether they can get into your messenger app or not. 

1

u/ephemeralmiko 1d ago

I only have very limited apps on my phone, and Signal is the only one that actually has personal info on it. 

1

u/frquency-equinox 13h ago

Changing the app icon from Signal settings > appearance > app icon and setting the app lock should be enough, but the app lock uses your lock screen password, so make sure it's an alphanumeric with at least one symbol.

2

u/upofadown 1d ago

From other messages I get that you would like to lock up your Signal app so you can use the phone in the normal unlocked state without risk of someone taking the phone away from you and then reading your Signal messages.

You might have the wrong medium here. Even if you use Molly it would be fairly inconvenient to have a bunch of instant messages show up when you finally log in. Your correspondents might have moved on to other topics by then and could be confused by your offline periods. It is hard to use instant messaging in a non-instant way.

You might consider something more offline. Say an email account that you have to log in to with a client that doesn't cache messages. It sounds like this is actually what you want here.

2

u/Chongulator Volunteer Mod 1d ago

Yep. Furthermore, if OP isn't keying in a cryptographically strong passcode each time they open the app, then the app-level passcode is just theater anyway.

1

u/convenience_store Top Contributor 1d ago

If you're worried about a thief stealing your phone while it's unlocked then it doesn't matter they will immediately factory reset your phone and try to sell it.

If you're worried about, like, "the government" stealing your phone and accessing your high level secrets in your signal messages then for most phones it doesn't even matter if it's currently unlocked, if it's been unlocked at all since the last time it was rebooted then your message history is very possibly accessible. And if the phone is more than a few years old then there's a good chance it doesn't matter if it's been recently rebooted either, there are exploits to unlock a lot of older phones. This isn't a signal issue as much as it is a phone hardware security issue, once the messages are on your phone your phone needs to access them to show them to you or process new incoming messages in the background and once that's going on you're at the mercy of your OS.

2

u/ephemeralmiko 1d ago

My threat model is more an abusive family member, not the government or anything.

The phone is a Pixel 8a running GrapheneOS.

1

u/convenience_store Top Contributor 1d ago

It probably depends on the technical sophistication of the family member, like if they're a software security professional vs. if they're a walmart cashier but in any case GrapheneOS has a reputation of being an exception to what I said above (i.e., more secure even after first unlock), then, if you are using it properly, but you still don't want to leave it sitting around unlocked.

0

u/ephemeralmiko 1d ago

I wouldn't leave it unlocked (and I have a 15s screen timeout), I'm worried about it being snatched out of my hands while it's unlocked. But thanks for your answers.

1

u/whatnowwproductions Signal Booster 🚀 1d ago

Lock it in the private space.

1

u/3_Seagrass Verified Donor 1d ago

Given your threat model that you describe in the comments, honestly I would just use Molly. Obviously you’re adding an additional trust requirement to your setup, but your main priority is protecting against a local attacker, not some online entity.

Besides that, I would advise using disappearing messages as much as possible so that even if your phone gets snatched, there isn’t much chat history to uncover. 

1

u/Lower-Sheepherder268 1d ago

I'd still love to have a separate application lock. Universe forbid I'm letting my daughter use my phone and a message pop up, she keeps shoulder surfing to try to see my unlock code. I've been having to rotate it constantly.

I wouldn't care if she had access to the rest of my phone, heck, I'd give her the code, I just dont need her going into signal and messaging my fellow activist peeps.

1

u/ephemeralmiko 1d ago

Isn't that what app pinning is for? The phone stays locked in one app and needs biometrics/PIN to unlock.

1

u/Lower-Sheepherder268 1d ago

If I wanted to pin one app, sure. But she uses multiple apps that I allow for her.

She's not old enough for her own phone yet, so it's a bit of a problem.

1

u/frquency-equinox 13h ago

Get some cheap used thing for her to use specifically and hide the app store(s)/put purchases behind a password so she can't accidentally buy or download things.

1

u/Unique-Exit4592 1d ago

App Lock helps by requiring another authentication step to open Signal but it's not the same thing as having the database encrypted with a separate key or password.

That's where Molly's additional database encryption is useful: even if the phone itself is unlocked the Signal database has another layer of protection.

1

u/frquency-equinox 13h ago

If they steal the phone while unlocked, they would need your lock screen password to get past the app lock, so use a strong lock screen password.

1

u/ephemeralmiko 13h ago

I do, but I'd heard that it's pretty trivial to just export Signal's message database since that isn't encrypted locally unlike with the Molly fork.

1

u/frquency-equinox 7h ago edited 7h ago

Signal's database is encrypted though. It decrypts when your phone is unlocked so you can read your messages, which is why it's important to have a strong lock screen password in general; it encrypts the entire device.

Molly just adds another layer on top of that with a separate passcode or password. But Molly doesn't have any official third-party audit I can find, unlike Signal, which probably means the code hasn't been professionally audited, so I wouldn't trust it, personally.

But if someone gets past your lock screen, it will be trivial to get past your app locks. GrapheneOS would provide additional protection by destroying everything in RAM on reboot.

1

u/Chongulator Volunteer Mod 4h ago

Someone holding your unlocked phone can see everything you can see. The best protection is to lock your phone and use a strong passcode. If an attacker can guess your passcode, it's game over.

-2

u/Late-End824 2d ago

I guess it depends on what crazy one in a million scenario you're dreaming up.

A. Someone steals your locked phone and somehow guesses/hacks your PIN?

B. Someone steals your unlocked phone out of your hand while Signal is in use.

Or C. Someone steals your unlocked phone out of your hand while it's not in use.

In A and B you'd be screwed because it would be open or they would know how to open it. In C. Presumably anything with a secondary lock would be safe for a while and would would probably have enough time to remote wipe the device.

Of course if you're living someplace that these scenarios are more common than lightning striking the ground next to, bouncing, and shooting straight up your ass, well, you may want to address your living conditions because quite frankly any of these have about the same odds as that lightning.

3

u/ephemeralmiko 2d ago

I'm talking about scenario C, and currently changing that isn't really an option.

2

u/usrbincomment 1d ago

It appears that you're not aware of your own privilege. I think people who live in South Africa or Brazil will be happy to explain how people steal phones out of hands while in use on the street. This isn't some crazy fever dream. It happens.

Telling people to move out of these countries is stupid and demeaning.