4 ms·
It's ludicrous that you need javascript enabled to download a secure messaging app.
by verbify 9y ago
It's ludicrous that you need javascript enabled to download a secure messaging app.
- mfwoods 9y agoFor those that don't want to enable Javascript, these are the hidden Linux instructions: $ curl -s https://updates.signal.org/desktop/apt/keys.asc | sudo apt-key add - $ echo "deb [arch=amd64] https://updates.signal.org/desktop/apt xenial main" | sudo tee -a /etc/apt/sources.list.d/signal-xenial.list $ sudo apt update && sudo apt install signal-desktop
- frabbit 9y agoHow are we supposed to verify keys.asc? (To be a bit more explicit: searching for either the pub (57F6FB06) or sub(0E46390F) keys on hkps.pool.sks-keyservers.net returns no result)
- mfwoods 9y agoJust because it's on a keyserver doesn't mean it's trustworthy. Keyservers do no verification of any kind on the keys they host. If you(r system) trust the certificate that https://updates.signal.org/ https://updates.signal.org/ is using, you should be confident that you are getting the correct keys. (You shouldn't trust a stranger on the internet, but I am getting the same keys when I download them.)
- acdha 9y agoYou are willing to run their code on your computer with full access to your data but not in the heavily-sandboxed browser environment?
- scott_karana 9y agoVerbify didn't say that at all. It's ludicrous that you can't download a security-focused app when your browser settings are unusually secure. ;)
- acdha 9y ago> It's ludicrous that you can't download a security-focused app when your browser settings are unusually secure. ;) Security is about threat models: if you don't trust the code they write on their website, you shouldn't trust the code they shipped in the app.
- verbify 9y agoA casual look shows they're also loading JavaScript via bootstrapcdn.com and googleapis.com. Security is also about attack surface reduction.