4 ms·
I noted this in another comment, but if they _did not_ update the code in production, they ran with known vulnerabilities in the server side for many months: ht
by dogecoinbase 5y ago
I noted this in another comment, but if they _did not_ update the code in production, they ran with known vulnerabilities in the server side for many months: https://github.com/signalapp/Signal-Server/commit/3432529f9c018d75774ce89f3207b18051c26fe7#comments https://github.com/signalapp/Signal-Server/commit/3432529f9c...
There's no good option here.
- cptskippy 5y agoInterestingly one of the comments in that thread refers to the server code as a reference implementation. This implies that Signal's server code isn't opensource, and that this code is just a reference implementation. The readme.md on the repo doesn't really clarify one way or another on the matter.