Signal Introduces Encrypted Local Backups for iOS and Desktop Apps
What Happened – Signal version 8.30 adds end‑to‑end encrypted, on‑device backup support for iOS and desktop clients, completing the feature across Android, Linux, macOS and Windows. Backups are protected by a user‑generated recovery key; hosted backups also use a rotating TEE‑based key for forward secrecy.
Why It Matters for Trust & Control Assurance
- Demonstrates a concrete control for data‑at‑rest encryption and key‑management that can be continuously monitored and evidenced.
- Provides a defensible audit trail for backup integrity, helping organizations prove compliance with data‑protection objectives across multiple frameworks.
- Highlights the need to treat recovery keys as high‑value credentials, reinforcing identity‑access controls and secure storage policies.
Who Is Affected – Consumer and enterprise users of Signal’s secure messaging platform (technology, communications, and any sector that relies on encrypted chat).
Recommended Actions
- Verify that encrypted local backups are enabled and that recovery keys are stored in a secure, access‑controlled vault.
- Map the backup encryption and key‑management process to your data‑protection control objectives (e.g., encryption of data at rest, key lifecycle management).
- Capture configuration evidence and integrate it into your continuous control‑assurance program for audit readiness.
Source: BleepingComputer
Technical Notes – The backup format is unified across platforms; media files are stored separately and de‑duplicated. Disappearing messages are excluded from backups. No new CVEs are disclosed. Source: same as above