6 ms·
Signal needs to release all the infra automation code behind their backend. How they setup and manage it all should not be secret. It also makes it easy to rebu
by purpleidea 13d ago
Signal needs to release all the infra automation code behind their backend. How they setup and manage it all should not be secret. It also makes it easy to rebuild if for some reason they are compromised. They've ghosted multiple people about this question. There's no reason a 501(c)(3) shouldn't release it.
- s0ss 13d agoI’m not sure their tax status is the justification your argument needs.
- fsflover 12d agoIt's just an additional argument.
- deleted 13d ago[deleted]
- what 13d agoOpenAI is 501c3, should they also be required to release everything?
- alightsoul 13d agoYes
- gbriel 13d agoNon profit doesn't necessitate open sourcing their whole product. If you don't like that, don't donate. As long as they are transparent about their decisions that is the only obligation they have.
- akoboldfrying 13d agoPerhaps it shouldn't necessitate it, but I can't think of a good reason why not. If it were expensive to release it, that would be a reason. But it costs roughly zero dollars to create a public repo on GitHub and a cron job to push to it once a day. Making the system public potentially increases the likelihood of a hack, which would be bad for Signal users. But relying on this argument to keep the source secret is, I think, a confession that your security is below par. Or to put it the other way round: A secure software system remains secure even if its source code is public, so making your source public is a strong signal that you are confident in your security measures. Security isn't something I expect all non-profits to focus on, but I think it would be telling for Signal to hide behind this reason. What other reasons are there?
- Jolter 13d agoHow about they: 1. Don’t want hack competitors launching products using their code 2. Don’t want the resulting fracture in the community If I were Signal I wouldn’t want either of those.
- akoboldfrying 12d ago1. A for-profit company rationally doesn't want competitors launching products using their code. Why would a non-profit care at all? 2. An app like Signal depends completely on network effects, so there's even less motivation for a community-fragmenting fork than in most OSS cases, where you'll notice that forks are already rare. There would have to be something very weird or contentious happening with the original codebase for people to want to fork it -- otherwise it's in no one's interests.
- purpleidea 12d ago> Non profit doesn't necessitate open sourcing their whole product. If you don't like that, don't donate. As long as they are transparent about their decisions that is the only obligation they have. Actually you're mistaken. Under the 501(c)(3) tax code rules, they are required to act in the public good. Nobody has sued them to enforce this though, but I'd at least like them to acknowledge the game they're playing by ghosting us all on this.
- TFNA 12d agoAmerican 501c3 law is extremely lax compared to analogous structures in the EU. A number of 501c3s are run as sinecures where a board (self-selecting, so no input from the membership) just hires its friends for well-paid positions that involve little work. Because the law is so lax and permissive, making a case that a given org is not acting in the public good is extremely rare and uphill.
- NooneAtAll3 13d ago"open" is literally in the name, so yes
- Grombobulous 13d agoApple should make their products edible as well.
- mertenvg 13d agoPretty sure that was Blackberry's downfall
- monocasa 13d ago'Apple' was a metaphor to Newton. 'Open'AI was meant as a promise; one that they've since broke both to some of their founders as well to the general populace. Reminding people of that broken promise doesn't seem that wild.
- latexr 12d ago> 'Apple' was a metaphor to Newton “Apple” was a non-intimidating name that would appear early in the phone book. It had nothing to do with Newton, that logo came after the name. https://en.wikipedia.org/wiki/History_of_Apple_Inc https://en.wikipedia.org/wiki/History_of_Apple_Inc. > According to Wozniak, Jobs proposed the name “Apple Computer” when he had just come back from Robert Friedland's All-One Farm in Oregon. Jobs told Walter Isaacson that he was "on one of my fruitarian diets," when he conceived of the name and thought "it sounded fun, spirited and not intimidating ... plus, it would get us ahead of Atari in the phone book."
- monocasa 12d agoEither way, it wasn't intended to be a promise to the public to be held to the same way as OpenAI's name was.
- 12d ago
- vlovich123 13d agoOpenAI is a 501c4 not a 501c3. Also the structure is much more complicated for OpenAI. Nevertheless the point stands - I don’t see what relationship company organizational mission has with their technical responsibilities. Indeed, if the open sourced everything, standing up a clone would be easier which creates funding risk due to a race to the bottom of people who didn’t invest into the R&D investing very little additional to compete.
- throwaway2037 12d ago> OpenAI is a 501c4 not a 501c3 This is incorrect. OpenAI is actually registered as a 501(c)(3) public charity, not a 501(c)(4) social welfare organization. (Source: Bloomberg Law) > Also the structure is much more complicated for OpenAI. However, this is correct. Their corporate structure is very complex. Here is a screenshot from OpenAI's corporate structure explanation page (now taken down): https://images.axios.com/fbMDxci4KDAoYxM_v61sPi9jSVs=/0x0:1920x1080/1920x1080/2023/11/18/1700315854498.png?w=3840 https://images.axios.com/fbMDxci4KDAoYxM_v61sPi9jSVs=/0x0:19...
- zx8080 12d agoIs it a joke to consider openai as non-profit corporation?
- ezst 12d agoSignal is there for power and control, not for its users, otherwise they would welcome the usage of third party clients, and generally, encourage decentralisation measures like self hosting, federation and account portability. Yep, they have nice engineering blog posts, they are also US-incorporated, extensively centralised in AWS and subject to the cloud act, which together negates, or largely diminishes claims about being privacy conscious.
- fredski42 12d agoDoes the perfect messaging tool exist (100% e2ee encrypted and decentralized and open)?
- zx8080 12d agoXMPP. Run your own (federated) server, chat with anyone outside it, with e2e encryption.
- fsflover 12d agohttps://matrix.org https://matrix.org is used by public agents of France's central administration, Germany's national healthcare system, Germany's armed forces, the Swedish Social Insurance Agency and more: https://en.wikipedia.org/wiki/Matrix_messaging https://en.wikipedia.org/wiki/Matrix_messaging
- ezst 12d agoRealistically nothing is ever perfect, but XMPP comes very close. You've got Signal-introduced double-ratchet encryption if forward secrecy is your jam (so it's as "E2E-secure" in practical terms) and you've got a healthy ecosystem of independent client and server implementers, and service providers to choose from.
- Tomte 12d agoIs there a messenger that allows anonymous group chats, i.e. for union organizing in a company? As far as I can see, you can invote people to a group chat using QR flyers, but your Signal profile is visible to everyone in a chat, so everyone knows what Tina in marketing thinks about it. Because nobody is going to have a burner phone with a data plan for a separate Signal identitiy.
- crossroadsguy 12d agoNot only that. I also question how they pick new features to implement. For example usernames - I am not going to trust another "private" IM app username feature same as what Telegram and WhatsApp questionably chose. Compromise on this? Well, then even WhatsApp and Telegram are good enough with compromises. Separate usernames completely from phone numbers. Period. There's a reason Signal is still "US based". No, I am not talking about some CIA/NSA/DoD/tom/jerry funding conspiracy, just good old human obstinacy and hubris. They don't give a f about who uses it, it's about who makes and maintains it all.
- sm-silversight 12d agoWhy would the CIA bother?
- chinathrow 12d agoContext?
- ale42 12d agoSome people believe that there's the CIA is behind Signal.
- sire-vc 12d agoThe CIA certainly uses Signal, which is why privacy advocates who think the US government will go after it are idiots. Same thing for Tor.
- sm-silversight 12d agoI'm being cheeky and implying that the reason signal's active backend is not disclosed as hoped for in a prior poster's comment is because the CIA (or other intelligence) is involved in it.
- 0xbadcafebee 12d agoWhy do you want infra automation code?
- autoexec 12d agoSignal ghosts people or gets very evasive on other questions to. They've also refused to update their privacy police since they started permanently keeping sensitive user data in the cloud. They can only scream "Don't trust us" so loud.
- 1vuio0pswjnm7 12d agoWhen news leaked that federal agents and contractors had access to WhatsApp "end-to-end encrypted" messages using the "Signal Protocol", WhatsApp users sued Meta Faced with mounting statutory damages per violation for wiretapping claims under CIPA and Pennsylvania's wiretap act, Meta forced arbitration https://ia801900.us.archive.org/6/items/gov.uscourts.cand.466549/gov.uscourts.cand.466549.1.0.pdf https://ia801900.us.archive.org/6/items/gov.uscourts.cand.46... "48. After Meta acquired WhatsApp in 2014, WhatsApp partnered with Open Whisper Systems to integrate the Signal Protocol, which is an end-to-end encryption cryptographic protocol, into the WhatsApp platform.26 The integration of the Signal Protocol onto the WhatsApp platform was completed by April 5, 2016.27 58. Recent reporting has confirmed that WhatsApps numerous promises that no one other than intended recipients has access to users communications is false. Indeed, contrary to WhatsApps repeated assurances otherwise, Meta, WhatsApp, their employees, contractors, and/or third-parties personnel have access to users WhatsApp messages.32 59. According to whistleblower accounts reported to federal investigators, employees of Meta and WhatsApp and third-party contractors employed by Accenture are able to access the contents of users messages, contrary to the privacy representations made by the company.33 60. Former Meta contractors reported to special agents with the U.S. Department of Commerces Bureau of Industry and Security that they and some of their colleagues had broad access to the substance of WhatsApp messages that were supposed to be encrypted and inaccessible.34 The two sources confirmed that they had employees within their physical work locations who had unfettered access to WhatsApp, and one stated that she spoke with a Facebook team employee and confirmed that they could go back always into WhatsApp (encrypted) messages.35 61. Moreover, these whistleblowers have outlined much broader access by Meta employees and third-party contractors than the limited access described in WhatsApps Privacy Policy and website.36 32. Jake Bleiberg, US Has Investigated Claims WhatsApp Chats Arent Private, Bloomberg (Jan. 29, 2026, at 16:22 ET), https://www.bloomberg.com/news/articles/2026-01-29/us-has-investigatedclaims-that-whatsapp-chats-aren-t-private https://www.bloomberg.com/news/articles/2026-01-29/us-has-in.... 33 Id. 34 Id. 35 Id. 36 Id." Unless users control the client software, "end-to-end encryption" is just marketing Closed source apps and backends by US companies means communications can be monitored if US law requires it A "backdoor" in the client app can be easily installed remotely by the company through an "automatic update"