diff --git a/docs/real-time-communication.md b/docs/real-time-communication.md index fa1be7de..9ea60f35 100644 --- a/docs/real-time-communication.md +++ b/docs/real-time-communication.md @@ -53,6 +53,15 @@ Signal requires your phone number for registration, however you should create a You can optionally change the **Who Can Find Me By Number** setting to **Nobody** as well, if you want to prevent people who already have your phone number from discovering your Signal account/username. +
Signal Desktop Warning
+ +Signal's desktop client is notably [less secure](https://discuss.privacyguides.net/t/signal-stores-your-decryption-key-in-a-plain-text-file-on-macos/19309/69) against local malware compared to its mobile apps. While no messenger can ever provide complete protection against local malware with sufficient access, Signal Desktop is built on Electron and does not utilize native OS data protection features like strong application sandboxing or database encryption. This could mean that even malware with very limited (read-only user level, instead of full root) privileges could potentially compromise your messages. + +For most people this is only a minor concern (if you have malware on your device, you probably have bigger problems). If you are particularly concerned about malware or physical/targeted attacks, you may be better off using the mobile apps exclusively. + +