4 ms·
> there is no way to verify that it works in the way that it does Since we're specifically talking about Signal, I think that it's worth mentioning that Signal
by saulrh 2y ago
> there is no way to verify that it works in the way that it does
Since we're specifically talking about Signal, I think that it's worth mentioning that Signal is uniquely predictable here. They published their entire cryptosystem, it's been extensively inspected by the cryptography community, there are multiple open-source implementations that agree with the published mathematics, and I strongly suspect that more than a few people have sat down to verify that the bytes coming out of the app are actually produced by the published protocols. Claiming that that's not "working the way it does" is reaching out into territory along the lines of Trusting Trust, the unproven existence of trapdoor functions, and the Problem of Induction.
- newaccount74 2y agoRight. There is no way for me to verify that the Signal app isn't actually a trojan created by a US agency with a clever marketing team. It sounds far fetched, but it wouldn't be the first secure messenger that was later revealed to be a covert spying device. I still use the app, because I trust Signal more than Facebook, but the encryption isn't why I trust them.
- nullc 2y ago> there are multiple open-source implementations No. Signal locks not not just third party software but also builds of their own "open source" code via timebombed forced updates. It's somewhat impractical to use signal except via blinding accepting updates from them. As a result every signal user is sadly quite vulnerable to getting pushed a bad update, particular since app store policy changed to require the app store itself being able to sign updates. Signal could mitigate this by allowing third party clients and/or not timebombing support.