Signal Adds Encrypted Local Backups and Cross‑Platform Restore for iOS, Desktop, and Android
What Happened – Signal 8.30 introduces on‑device encrypted backups for iOS and desktop, unifies the backup format across Android, iOS, Linux, macOS and Windows, and adds a cross‑platform restore capability. Backups are protected by a user‑controlled recovery key; hosted backups also use a daily‑rotating supplemental key stored in a Trusted Execution Environment (TEE) to provide forward secrecy.
Why It Matters for Trust & Control Assurance
- Demonstrates a concrete control for protecting data at rest – a key requirement in continuous‑control‑assurance programs.
- The recovery‑key model and TEE‑based supplemental key give auditors verifiable evidence of encryption, key‑management and forward‑secrecy practices (NIST CSF 2.0 Protect).
- Enables organizations to document a tested backup‑and‑restore process, supporting defensible audit trails for data‑integrity and availability requirements.
Who Is Affected – Consumer‑focused messaging services, enterprise‑messaging deployments, and any organization that relies on Signal for secure communications.
Recommended Actions
- Review your backup‑encryption policies and ensure recovery‑key handling aligns with internal key‑management standards.
- Incorporate Signal’s backup‑restore workflow into your periodic control‑testing schedule and capture evidence for audit readiness.
- Map the encryption and key‑rotation controls to the relevant control objective in your framework of record (e.g., NIST CSF Protect or ISO 27001 A.10).
Technical Notes – The on‑device backup format stores media in a deduplicated folder, reducing storage overhead. Hosted backups encrypt data with a user‑provided recovery key plus a daily‑rotating key in a TEE; the supplemental key cannot decrypt backups alone, providing forward secrecy. Disappearing messages older than 24 hours are excluded from backups. Source: Help Net Security