Signal should change this, but it's typical of the traditional desktop OS security model in which applications running under the user's account are considered trustworthy. Security-oriented software like Signal should take a more hardened approach, but this is not some glaring security hole.
Maybe its time to rethink desktop security. I realize that there is credential manager on windows, keychain on mac, and similar on gnu/linux; even with that it seems for a lot of services "all" you need to do is steal a cookie and all of a sudden you are someone else.
Under normal circumstances I wouldn't expect any privacy between processes on a desktop OS under the same UID.
If you use Chrome's password manager on Windows your password database is unlocked with your password upon login and is available to every process you run.
There's only so much you can do, as an app, to protect against OS deficiencies.
The desktop app on Windows is a sacrifice of security for convenience.
I don't see what the big deal is. I store all kinds of sensitive information in plain text. SSNs, credit card numbers, birthdates and religious and political affiliation information.
The guy I bought it all from said it was okay, he stores it in plain text, too. (I'm joking, of course! Any information about you all that I've bought on the dark web, I'm storing responsibly.)
I trust my computer and operating system. And there are several other keys and credentials stored on that laptop. I think it's better for me to have a file that I can backup and understand how the encryption works, than to do some trickery to hide it mostly from me and maybe a bit from malware, or tie it to some hardware TPM device or something. I'm always not sure if I should rely on those too much.
But surely if it was stored encrypted, it would still need a key to unlock that info. Which would be on your PC. And could therefore be used by anything else to unlock your data.
The only safe way would be encrypt it with a password that only you know, and you'd need to enter before getting back into the software. And there couldn't be any "I forgot my password" function either. You lose it, the data is gone.
Yes, you don't understand that the story is about the Mac client and then later it was found out that Linux and Windows are equally affected. Did you even attempt to read it?
I told the guy I buy a certain thing that should be legal in this state from that trusting Signal is a bad idea and he should use some coded language if we were going use it. I do anyway, but I doubt that matters.