5 ms·
How can we verify that the app on the App Store was compiled with the github source? (So all the code can be examined.)
by 13throwaway 13y ago
How can we verify that the app on the App Store was compiled with the github source? (So all the code can be examined.)
- chrisballinger 13y agoYou could theoretically clone the source, check out the release tag, compile it, and then compare the checksum of the binary of the .app file, but I'm not sure if that would even generate the same exact file or not. You might also need a jailbroken device to decrypt and extract the App Store binary. If you really want super paranoid level security, communicating digitally is probably not your best bet anyway. Here's the SHA1 checksum of the compiled binary from the latest release (2.0): f9347ae51c3276f4b34fba0be7c0648f20c8c11e /Applications/ChatSecure.app/ChatSecure
- 332485 13y ago> super paranoid level security Considering the fact that Apple is in the NSA wiretapping program and involved in secret tracking [1], don't you think it's unfair to call someone who's asking a way to verify if Apple isn't messing with the code "super paranoid"? [1] https://en.wikipedia.org/wiki/IPhone#Secret_tracking https://en.wikipedia.org/wiki/IPhone#Secret_tracking
- rorrr2 13y agoThere's no easy way. Even if you do verify it, there's no guarantee Apple won't push an update with a backdoor because NSA asked them to. That's why it's better to use Crypto.Cat - its source is the executable. Verifying the hash is enough to make sure the source code didn't change.
- 13throwaway 13y agoI would love to use Crypto.cat, but there is not a mobile app yet. When there is a mobile app it will have the same problem.
- sneak 13y agoEven then, Apple could just keylog certain applications at the OS level, cryptocat and unmodified-binary ChatSecure included.
- rorrr2 13y agoYes. Unless you're running an open-source OS and open-source hardware (and trust the manufacturer and the compiler), you are not safe.
- sneak 13y agoThough it's a lot easier to compel Apple to silently push a wiretap update to a handset than to have, several months/year ago, engineered a secret backdoor into a chipset... You've gotta draw the line somewhere (unless you're rms). I would venture to say an open source OS and applications on worldwide-deployed hardware in the hundreds of millions count is probably safe enough for my purposes.