3 ms·
> The Signal code was closed source for longer than a year (from April 2020) This absolutely untrue. Signals source has NEVER been closed source. The Signal se
by rOOb85 5y ago
> The Signal code was closed source for longer than a year (from April 2020)
This absolutely untrue. Signals source has NEVER been closed source. The Signal server source code(which isn't special and doesn't change that often) just had no public commits. The Signal client source code(what matters and makes Signal secure) was frequently updated.
> Signal may be open source at times,
Again, Signal has always been open source.
- izacus 5y ago> The Signal server source code(which isn't special and doesn't change that often) just had no public commits. So it was opensource... you just couldn't see the source running on the servers? Yeah, makes sense. Right.
- sneak 5y agoWell seeing as you don't have access to the ME, no amount of application code being published will mean you can see the source running on the servers. This is a red herring. The client source code is the only thing that's really relevant in an e2e encryption model, anyway. Regardless, 100% of the production versions of the Signal server software have been published under free software licenses, so I'm not sure what you're arguing.
- grayhatter 5y agoThis is not true, You contain just as much if not more value from building the graph of people who communicate with each other then knowing the contents of their communication. But I think what they're trying to say is because signal prevents any user from being able to use the signal app with servers they the user control. You're stuck with trusting the people running the servers because they say they won't do anything wrong. The whole reason you say the client is what matters is because it's something the user doesn't need to trust somebody else won't do something wrong. if I can build my own client and validate myself The security doesn't depend on blindly trusting somebody else because they say it's safe to do so. A well designed encrypted protocol doesn't depend on blind trust in some service. The main signal app requires blind trust in the servers they control.
- novok 5y agoCurrently you can get the metadata graph and contents of conversations for most messenger usage today. Now with signal and other E2EE messengers, you can just get the metadata graph, maybe. Not using the standard set of servers makes you stand out in a different way metadata wise, and more vulnerable, because you don't have as much labor available to secure your personal network, which is what your hinting at. It's partly why tor is a public network, because they want more noise in metadata analysis, and why you want to use VPN providers, so it's not just "you" that is aggregating your traffic. The 3rd era will do both in a usable way, but usable ones don't really exist yet. All you have is research messengers. One step at a time. Perfect is the enemy of good, or something better.
- grayhatter 5y ago> Currently you can get the metadata graph and contents of conversations for most messenger usage today. Phrased differently; Other messengers don't protect privacy so it's acceptable for this one claiming security to break privacy too. > Now with signal and other E2EE messengers, you can just get the metadata graph, maybe. Not using the standard set of servers makes you stand out in a different way metadata wise, and more vulnerable, because you don't have as much labor available to secure your personal network, which is what your hinting at. No, that's not what I'm hinting at. I'm complaining signal pretends it's primary focus is privacy any security, but fails at some of the most basic designs! If someone is targeting me specifically they can own my server, and I'm screwed. But using my server; if they own Signal, they don't get me for free. The inverse is correct as well, if they're targeting me, and they own me. They might not put forth the effort to own Signal. And if your opposition includes people who can server a sealed warrant, hacking into signal might not even be needed. > It's partly why tor is a public network, because they want more noise in metadata analysis, and why you want to use VPN providers, so it's not just "you" that is aggregating your traffic. What? > The 3rd era will do both in a usable way, but usable ones don't really exist yet. All you have is research messengers. > One step at a time. Perfect is the enemy of good, or something better. No, that's not true about security. No security is better than half-assed security. Especially if you don't know it's half-assed.