4 ms·
There's a comment on that blog post that says "what is meant by 'the server'?" That's probably the best possible question here. What's the point of building ano
by jacobquick 13y ago
There's a comment on that blog post that says "what is meant by 'the server'?" That's probably the best possible question here. What's the point of building another messaging system and key distribution method if they can show up with a secret subpoena and do whatever they want with your servers?
- m_ram 13y agoThe client is open source [1], so you can verify that it's doing what they claim. You can also build it yourself if you want to be really careful. I don't think messing with the servers would do any good (except for metadata) when the clients are handling the encryption. [1] https://github.com/WhisperSystems/TextSecure/ https://github.com/WhisperSystems/TextSecure/
- zokier 13y ago> would do any good (except for metadata) But metadata is important
- moxie 13y agoMetadata is important, but right now TextSecure uses SMS/MMS, so "the server" is your telco. I don't think it's possible for anything we do server side to be worse.
- jacobquick 13y agometadata is what they are looking at now. they collect everything else so they can look at it later when they break the encryption
- zokier 13y agoFrom what I gather the system is built so that "the server" does not hold any secrets. I suppose there is a possibility of metadata leakage and/or denial of service, but the message bodies would remain safe due the end-to-end encryption.