4 ms·
As a concrete reminder, Signal didn't publish the source for their server-side from 20 April 2020 to 6 April 2021 while they secretly added a cryptocurrency pay
by dogecoinbase 4y ago
As a concrete reminder, Signal didn't publish the source for their server-side from 20 April 2020 to 6 April 2021 while they secretly added a cryptocurrency payment system, which Moxie denied they were doing in January 2021 (I'm on phone at the moment, happy to provide cites later but truly, they're not hard to find).
Don't trust Moxie; don't trust the server side of Signal.
- sschueller 4y agoI am in the same boat. I don't trust Moxie.
- growse 4y agoThe whole point of the design is that you shouldn't have to trust the server.
- ls15 4y agoThen why no custom clients?
- growse 4y agoBecause they provide no guarantees around the stability of the protocol, and presumably don't want to drag around the weight of a load of poorly-maintained clients that break all the time. Besides, it's their service, they get to say who and how they connect.
- anjbe 4y agoDon’t trust the server side of any service. Open source or not, federated or not, it’s impossible to verify that a server you talk to runs the code it says it does. Which leads to one of the selling points of Signal: that the client is designed to expose as little metadata as possible to the server. Sure, the Signal servers could be slurping up IP addresses and timings despite advertising that they don’t. But I can’t think of a single alternative service that can guarantee otherwise, and that problem is compounded by clients that leak much more metadata than Signal.
- zaik 4y ago> federated or not I'm pretty sure I can check what code my XMPP server in my room runs. Not a freedom you have when using something like WhatsApp or Signal.
- anjbe 4y agoI have a modicum of trust that the sensible reader understands that given the phrase “federated or not,” the subsequent phrase “a server you talk to” refers to external servers in the federation that your self‐hosted server talks to.
- bzxcvbn 4y agoIf you want to talk to anyone but yourself, you either have to trust someone else's server, or ask someone to trust yours.
- JadoJodo 4y ago> Don’t trust the server side of any service. This comes across as dismissive of the criticisms outlined by GP in favor of more general critiques about owning your own data. Yes, "The cloud is just someone else's computer", but GP gave specific criticisms about Signal. This would be no different from someone replying to a criticism about Telegram ("They rolled their own crypto; Don't trust the server side of Telegram!") with "Don't trust the server side of any service.". Yes, it's true, but it doesn't address the issue raised.
- anjbe 4y agoIt’s strange that’s how it came across to you. The difference compared to your analogy is that Telegram’s self‐rolled crypto is a problem many messengers don’t have, and it can’t be mitigated by the client. Whereas the possibility of malicious things being done on Signal’s server end is a problem shared by every messenger, and Signal works hard to mitigate this by pushing smarts like contact handling entirely to the client side. I also don’t see why you brought up “owning your own data.” I already discussed that the same “don’t trust external servers” axiom applies to self‐hosted federated systems as well.