3 ms·
Thank you for the breakdown. Since we're on the topic of having to trust X, is there any reason to believe X wouldn't insert some code into the client JS (behi
by hmry 1y ago
Thank you for the breakdown.
Since we're on the topic of having to trust X, is there any reason to believe X wouldn't insert some code into the client JS (behind some per-account flag) to exfiltrate your key or PIN, if they were ordered to do so?
I wouldn't rely on a website as a secure communication client, that seems like a job for an open-source native application. But I'm no expert.
- mjg59 1y agoOh, yeah, with no infrastructure to actually attest to the website (or the app) being trustworthy you're inherently placing trust in Twitter. Use Signal.
- mort96 1y agoI think Signal is as secure as is reasonably possible, but it's worth noting that even with Signal, you can't actually verify that the app you've downloaded reflects the source code. The GitHub issue about reproducible builds is closed as not planned: https://github.com/signalapp/Signal-iOS/issues/641 https://github.com/signalapp/Signal-iOS/issues/641
- mjg59 1y agoThe Android build is reproducible, iOS is (to the best of my knowledge) hard work for a number of reasons.