5 ms·
The first step would probably involve getting a PhD in cryptography...
by angott 6y ago
The first step would probably involve getting a PhD in cryptography...
- bawolff 6y agoThere's a lot more than just crypto. Its much more common for systems to fail in the supporting code then it is for the crypto to be wrong. So first step is probably learn reverse engineering and verify the crypto is being used correctly. Then after that get a phd in cryptography.
- colordrops 6y agoThe source code is available.
- bawolff 6y agoFair enough. The point still stands you should do normal source code auditing before worrying about the crypto aspects.
- nautilus12 6y agoUgh...now I have to get a phd in "source code" too??
- antpls 6y agoGreat. So now, you need a Software Engineering degree AND a cryptography PhD
- sadfklsjlkjwt 6y agoUnless the build is reproducible it would be smart for a paranoid person to use the published source code only as a comparison with the decompiled app.
- sigmar 6y agoThe build is reproducible: https://github.com/signalapp/Signal-Android/blob/master/ReproducibleBuilds.md https://github.com/signalapp/Signal-Android/blob/master/Repr...
- jhoechtl 6y agoI file that under snarky comment. Certainly not required. A PhD will teach you a lot about methodology but not necessarily the technical details required and involved in secure multi-party or P2P messaging.