4 ms·
And the counterpoint is? ‘People should give Google/Apple root access on their devices to run this new secure messenger’?
by claudius 10y ago
And the counterpoint is? ‘People should give Google/Apple root access on their devices to run this new secure messenger’?
- eganist 10y ago> And the counterpoint is? ‘People should give Google/Apple root access on their devices to run this new secure messenger’? I feel like you might've misstated your intended point, but in any case: - Most threat models exclude the situation which you're discussing here because risks are generally low and, in the event of such a threat becoming material, the entity is probably screwed regardless of whether that threat is considered due to the costs of mitigation. (Seriously -- how would a company or person mitigate this short of independently auditing the code for the OS? Or building their own? And what happens after you look at the code? Do you then look at the hardware too? How low would you go? How low would your attackers go, for that matter?) - If you're the target of attackers who would actually try to gain access to your device through compromising the device maker, you've got bigger problems. The philosophical argument doesn't really work here because there's no practical solution that anyone can (or would, really) adequately fund. P.s. just to clarify, I'm not tptacek.
- sseppola 10y agoSorry, I don't understand. What do you mean by "give Apple/Google root access"? I've always assumed they already have that.. if no, how does OWS give them root access?
- e12e 10y agoYou can compile Signal yourself, and install it on a rooted phone, running presumably a Linux kernel and some Android/ASOP sub-system. In that case, excepting base-band backdoors and a few other details, Google won't have access to your phone at all (assuming no Google services etc here). OWS doesn't then allow you to use their servers for routing/discovery etc - so you need to run your own servers, and set up a different network that cannot federate with the one users of the Google Play Appstore version of Signal use. If you do that, and install eg. the F-Droid store, you've now given another actor (the F-Droid store) access to your phone. OWS argues that in general you're less likely to manage to run a safe, patched system this way.
- haffenloher 10y ago> You can compile Signal yourself, and install it on a rooted phone [...] OWS doesn't then allow you to use their servers for routing/discovery etc ? That's a misunderstanding. You can of course use the official servers with your self-compiled version. (side note: I also don't think your phone needs to be rooted for this)
- e12e 10y agoOk, that makes sense. It's only compiled binaries distributed through third party app stores that cannot (should not) use the official servers?
- haffenloher 10y agoYeah, they prefer if you don't distribute your builds (i.e. something named Signal and / or using their servers) to other people (because they don't actually know what's inside the builds, they've got no update channel, etc.)