3 ms·
> Thanks to Signal's security posture, global protection from weak ciphers, buffer overflows, and even SGX, is just one software update away. Conversely, thank
by kemonocode 6y ago
> Thanks to Signal's security posture, global protection from weak ciphers, buffer overflows, and even SGX, is just one software update away.
Conversely, thanks to Signal's centralized model, implementations of backdoors are also one software update away. By the time the "nerds" find out, it'd probably be far too late and lives could be at stake.
It's unfortunately such the nature of the beast that being half-hearted about security does not yield a half-secure product, or a product that's fully secure against half the hostile actors, it yields a product that only gives the presumption of safety, which is far more dangerous.
I use many messaging services in my life as security absolutism leads to a very miserable, very paranoid life, but my expectations are accordingly tempered when I use them, and I let my contacts know my expectations too. Everyday chat? Sure. Sensitive, personal info? Maybe, depends on the exact topic. Trade/state secrets (if I were to handle them)? Hell no.
- bobbyd3 6y agoreputation and community trust sometimes counts for something? i get it but i also know that if the nerds find out no one would use Signal...
- thu2111 6y agoIf Signal's security boils down to reputation and community trust, why not just use WhatsApp or Facebook Messenger or really any chat product where the makers claim it's secure and private?