3 ms·
I don't believe Signal has a web app. Am I wrong? I understand the point about the app being distributed by the same people who run the service, but it's much
by Cyphase 2y ago
I don't believe Signal has a web app. Am I wrong?
I understand the point about the app being distributed by the same people who run the service, but it's much harder to hide shenanigans with a local app versus a web app, especially when the app is open source.
- Xelynega 2y agoWhen was the last time you verified an update to signal against the source code? The threat model is circumvented for people that do that before every update, but unless you're doing that they can push whatever code they want to your app.
- Cyphase 2y agoWhat's your point/goal with this and your cousin comments? Yes, of course at some point you need to trust a binary or verify yourself. I'm technically correct and you're technically correct. What are you getting at? Do you suggest people not use Signal? What do you suggest as an alternative? What should Signal do to change things? Splitting management of the app and service doesn't help much; a compromised browser, not co-owned with the services it accesses, is enough to eavesdrop on someone despite HTTPS.
- Xelynega 2y agoMy point is to make a comment on social media and get responses to see what other people think. All I'm getting at is that any company that distributes code to you and tells you they can't see your data is lying. They just don't want to access your data right now. I would suggest people understand this and position themselves accordingly security-wise. If that means not using signal because its not secure enough then ok. If that means continuing to use signal with the understanding that it's only secure until signal decides they want your data(or a gov forces them to), then ok Splitting management of an app and service is the exact solution. If signal can't control when to push updates to your phone then they can't control when they want to break encryption. In your compromised browser example we understand that browsers have an interest in imementing HTTPS correctly and treat them accordingly. That's part of the reason the market is dominated by 2 engines that do their development as much in the public as possible