Signal adds encypted local backup support to iOS, desktop apps
Signal has released version 8.30, completing the rollout of its secure backups feature across all supported platforms including iOS and desktop apps. This feature allows users to create end-to-end encrypted backups of their chats, either hosted by Signal or stored locally on the device. The backups require a recovery key for decryption, and hosted backups include an additional rotating key for enhanced security. The update introduces local encrypted backups to iOS and desktop, aligns Android backups to a cross-platform format, and improves media storage efficiency. The backup system excludes disappearing messages set to vanish within 24 hours. The new iOS client also supports direct encrypted iPhone-to-iPhone transfers via Wi-Fi Aware. This release marks the completion of Signal's first phase of its backups project.
AI Analysis
Technical Summary
Signal version 8.30 finalizes the deployment of its secure backup feature across Android, iOS, Linux, macOS, and Windows. Users can create end-to-end encrypted backups either hosted by Signal or stored locally on their devices. Hosted backups have size limits and use a supplemental rotating key inside a Trusted Execution Environment for forward secrecy, while local backups have no size restrictions but rely on a single recovery key that can decrypt all past backups. The update adds local encrypted backups to iOS and desktop apps and standardizes Android backups to the same format. Media files are stored separately to avoid duplication, and paying users can purge old media locally while retaining thumbnails. Disappearing messages set to vanish within 24 hours are excluded from backups. The iOS app now supports direct encrypted transfers between iPhones using Wi-Fi Aware. Signal engineers will now focus on improving other systems beyond backups.
Potential Impact
The feature enhances user data protection by enabling encrypted backups that require a recovery key for decryption, reducing risk of unauthorized access to chat histories. The use of a rotating supplemental key for hosted backups adds forward secrecy. However, the recovery key for local backups can decrypt all past backups, making it a valuable target for threat actors. The exclusion of disappearing messages set to vanish within 24 hours prevents their inclusion in backups, preserving intended message ephemerality. The update improves backup reliability and efficiency across platforms. There are no reports of active exploitation or vulnerabilities associated with this feature as of the information provided.
Mitigation Recommendations
No specific vulnerability or exploit is reported in this update. Users should securely store their backup recovery keys to prevent unauthorized access to their encrypted backups. Since this is a new feature rollout, users should follow Signal's official guidance on backup creation and recovery. There is no indication of required patches or fixes related to security issues in this release.
Signal adds encypted local backup support to iOS, desktop apps
Description
Signal has released version 8.30, completing the rollout of its secure backups feature across all supported platforms including iOS and desktop apps. This feature allows users to create end-to-end encrypted backups of their chats, either hosted by Signal or stored locally on the device. The backups require a recovery key for decryption, and hosted backups include an additional rotating key for enhanced security. The update introduces local encrypted backups to iOS and desktop, aligns Android backups to a cross-platform format, and improves media storage efficiency. The backup system excludes disappearing messages set to vanish within 24 hours. The new iOS client also supports direct encrypted iPhone-to-iPhone transfers via Wi-Fi Aware. This release marks the completion of Signal's first phase of its backups project.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Signal version 8.30 finalizes the deployment of its secure backup feature across Android, iOS, Linux, macOS, and Windows. Users can create end-to-end encrypted backups either hosted by Signal or stored locally on their devices. Hosted backups have size limits and use a supplemental rotating key inside a Trusted Execution Environment for forward secrecy, while local backups have no size restrictions but rely on a single recovery key that can decrypt all past backups. The update adds local encrypted backups to iOS and desktop apps and standardizes Android backups to the same format. Media files are stored separately to avoid duplication, and paying users can purge old media locally while retaining thumbnails. Disappearing messages set to vanish within 24 hours are excluded from backups. The iOS app now supports direct encrypted transfers between iPhones using Wi-Fi Aware. Signal engineers will now focus on improving other systems beyond backups.
Potential Impact
The feature enhances user data protection by enabling encrypted backups that require a recovery key for decryption, reducing risk of unauthorized access to chat histories. The use of a rotating supplemental key for hosted backups adds forward secrecy. However, the recovery key for local backups can decrypt all past backups, making it a valuable target for threat actors. The exclusion of disappearing messages set to vanish within 24 hours prevents their inclusion in backups, preserving intended message ephemerality. The update improves backup reliability and efficiency across platforms. There are no reports of active exploitation or vulnerabilities associated with this feature as of the information provided.
Defensive Guidance
No specific vulnerability or exploit is reported in this update. Users should securely store their backup recovery keys to prevent unauthorized access to their encrypted backups. Since this is a new feature rollout, users should follow Signal's official guidance on backup creation and recovery. There is no indication of required patches or fixes related to security issues in this release.
Technical Details
- Classification
- {"confidence":0.3,"severitySource":"default","classifier":"rss-v2"}
Threat ID: 6abc2f86680226ef68511e16
Added to database: 09/29/2026, 21:37:10 UTC
Last enriched: 09/29/2026, 21:37:16 UTC
Last updated: 09/30/2026, 03:18:38 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.