3 ms·
> If Apple/Google want to backdoor Signal they can do so, they can also backdoor your device in this case the signature check is irrelevant if you consider them
by rahrahrah 10y ago
> If Apple/Google want to backdoor Signal they can do so, they can also backdoor your device in this case the signature check is irrelevant if you consider them an adversary.
What? No...
Assuming you trust OWS you can check the APK signature.
A) Nuke everything
B) Install ASOP or other OS that you prefer.
C) Download and manually checked Signal's signature.
D) Transfer it to your device.
No need to trust Google. Am I missing something?
Listen, you always need to trust SOMETHING. If you don't trust Google or OWS you can read their code yourself, but then you're trusting the compiler, the OS, the hardware, etc. But I submit that of the above some are inherently more trustworthy than others, given their track record.
- dogma1138 10y agoOWS doesn't support this method of distribution nor should they. If you want to do it your way get the source from github and build your own damn client. If you just want to check that the google play apk is signed you can do that with the antoid sdk/jdk jarsigner works on apk files.
- deleted 10y ago[deleted]
- rahrahrah 10y agoOk, but it's STILL false that if google wants to backdoor you a signature check is irrelevant. Also, no need to get triggered mate, we're just having a conversation.
- dogma1138 10y agoNo one is triggered if Google wants to backdoor the apk they can since OWS doesn't distribute the apk on their on. The play store apk is signed the AppStore app is signed what else do you want to be signed?
- rahrahrah 10y agoYou said that the play sore APK is signed. Signed by whom? By OWS, right? So Google can't backdoor it. Again, what am I missing? Help me out. I might be making a reasoning mistake due to not thoroughly understading how these things work (I mean APK distribution)
- dogma1138 10y agoThey are signed by the same process as all other APK's on the store; using the play store developer keys that OWS received. Google can backdoor it because they control the distribution source and verification scheme. Google can push anything they want to your device that's a given. Sure you can "lock them out" if you build your own android from AOSP (and even that is doubtful) but if you want to get Signal you'll have to install Google Play and the rest of the Google services which in effect will allow Google to backdoor your device if they would so desire too. Now you can say well I can violate the EULA rip off the APK from the Google Play store on one device and copy it to my AOSP device and verify it there, you still can using Jarsigner; but this is not a distribution method OWS want or should support. OWS trusts that Google and Apple will not backdoor the binaries and devices that is an axiom they base their threat models on; for them it's more important that all users would receive updates and use an upto-date version of Signal since this how how OWS ensures herd immunity; everyone is running more or less their latest software; all the security features are in play; they don't need to support legacy client; everyone is happy. At the end it's simply a case of OWS distributes it's software via 2 channels Play Store and App store in both cases the binaries are signed and verified by the processes supported by Google/Apple. Alternatively OWS allows you to download the source code from their Github repo and build the version of Signal for IOS/Android and sign it with any key you want. So overall I don't see where do you want them to add additional signatures; what is your threat model? It would be too easy to say "don't try to teach moxie how to do crypto" but this won't be interesting to either of us, I'm really curious what is your threat model that you would like additional signature specifically by OWS and what do you want them to sign.
- rahrahrah 10y ago