I have a hard time understanding the benefits of the keyring (e.g. GNOME keyring). I get the convenience parts - I don’t have to enter password for something every time I want to use it (e.g. mounted encrypted drive) and I don’t have to create a secret for some background stuff (applications keys). But the problem is, if I understand it correctly, that every application has the same access to my keyring, so, in theory, a malicious application can just read my Signal key and they can just read all my Signal messages right? Is there a point, then, in encrypting e.g. local database (like Signal) if the key to that database is readily available anyway? Any input is welcome. thanks!

  • Mordikan@kbin.earth
    link
    fedilink
    arrow-up
    2
    ·
    3 hours ago

    I had to recheck the timeout mention, and you are totally correct.

    You can set it to timeout but the default for most distros appears to be that it stays unlocked which is crazy.