2 ms·
> That's true for literally all services The point is that your client should not send any information which you expect to keep private to their services. It i
by dependenttypes 7y ago
> That's true for literally all services
The point is that your client should not send any information which you expect to keep private to their services. It is the exact reason that we use e2ee rather than just tls for chats.
> The client builds are
Not fully, see https://signal.org/blog/reproducible-android/ https://signal.org/blog/reproducible-android/
> Reproducible builds for Java are simple, but the Signal Android codebase includes some native shared libraries that we employ for voice calls (WebRTC, etc). At the time this native code was added, there was no Gradle NDK support yet, so the shared libraries aren’t compiled with the project build.
> Getting the Gradle NDK support set up and making its output reproducible will likely be more difficult.
- UncleMeat 7y ago> The point is that your client should not send any information which you expect to keep private to their services. It is the exact reason that we use e2ee rather than just tls for chats. Yes. And Signal achieves this better than all the other major options, given the number of footguns in the other tools. If you are concerned about the client builds then run a decompiler. It's not hard. People have been auditing binaries for ages.