I don't know if Signal is completely safe. What if they were required to send out an update to the application that also transmitted data in cleartext to a third party. It would look exactly the same to the user.

As long as you don't have reproducible builds and there is no way for the community to verify that everybody is running the same code (using a separate process that is independent of the application vendor) this is incredibly difficult to guard against.

arstechnica.com/tech-policy/20

Follow

@loke What I dislike about Signal is the phone number requirement, making sure they can pin the user metadata to a person even if messages are safe from decryption.

Sign in to participate in the conversation
Qoto Mastodon

QOTO: Question Others to Teach Ourselves
An inclusive, Academic Freedom, instance
All cultures welcome.
Hate speech and harassment strictly forbidden.