4 ms·
Don't trust this any more than any other closed-source "encrypted" communication product (like Skype). If they control both the source and the backend, how can
by chrisballinger 13y ago
Don't trust this any more than any other closed-source "encrypted" communication product (like Skype). If they control both the source and the backend, how can you be sure it isn't compromised? How can you be sure it won't eventually be sold to the highest bidder?
Disclosure: I am the original author of ChatSecure, the only open source OTR+XMPP app for iOS devices.
- bajsejohannes 13y agoThey are planning on releasing the source "later when it's stable and good enough". Souce: https://twitter.com/brokep/status/354608029242626048 https://twitter.com/brokep/status/354608029242626048 Edit: But they will still control the server. (It's audited by third parties, but... yeah)
- coopdog 13y agoIf the client source proves that the message is properly encrypted though (they're using PGP), the servers can be as insecure as the open internet and it should be ok
- bajsejohannes 13y agoI agree. The reason I put in that last sentence is because I read this in their FAQ (https://heml.is/ https://heml.is/): > Distributing to other servers makes it impossible to give any guarantees about the security. Not sure what they're referring to.
- conformal 13y agowe've seen what happens when "3rd parties" audit stuff - think cryptocat... encraption :)