> At issue further up the thread was whether insisting on using Google Play to distribute Signal for security reasons was sound logic, right?
No. The assertion was that Moxie only wished to distributed on the Google Play store. I addressed this complaint. From my first comment in this sub-thread:
>> He only wants distribution via Google...
> Untrue. He only wants distribution through channels that provide the same security assurances and deployment features that Google does through the Play Store. [0][1][2]
You then went off on a tear about how the Play Store doesn't provide "guaranteed security", with the strong _implication_ that this fact means that distribution through either the Play Store or the App Store is no better than distributing through a Market that performed no malware scanning, stripped the developer-provided signature from the software they distributed, signed all software distributed in the Market with the same signing key, and (because their code signing system was automated, rather than manually run) kept that signing key online and on an Internet-accessible computer, rather than in cold storage that gets occasionally attached to an airgapped computer.
The difference in procedures is crucial.
> I have to say it isn't helping to persuade me...
Your rhetorical style strongly indicates that you're more interested in verbal sparring than transfer of information. Maybe some months or years down the road you'll go back, revisit conversations like this one, and grow to understand something new about computer security.
[0] https://github.com/WhisperSystems/Signal-Android/issues/127#...
[1] https://github.com/WhisperSystems/Signal-Android/issues/281#...
[2] https://github.com/WhisperSystems/Signal-Android/issues/127#...