Signal Server code on GitHub is up to date again
1–10 of 206 posts
Re: Signal Server code on GitHub is up to date again
#2Re: Signal Server code on GitHub is up to date again
#3Is there any mechanism to validate that the code running on Signal's servers is the same as on Github?
Re: Signal Server code on GitHub is up to date again
#4Is there any mechanism to validate that the code running on Signal's servers is the same as on Github?
Unless you're going to hire some independent auditor (that you still have to trust) it seems logically problematic.
Re: Signal Server code on GitHub is up to date again
#5Is there any mechanism to validate that the code running on Signal's servers is the same as on Github?
Re: Signal Server code on GitHub is up to date again
#6Is there any mechanism to validate that the code running on Signal's servers is the same as on Github?
Re: Signal Server code on GitHub is up to date again
#7Is there any mechanism to validate that the code running on Signal's servers is the same as on Github?
Re: Signal Server code on GitHub is up to date again
#8Is there any mechanism to validate that the code running on Signal's servers is the same as on Github?
How would that work? You'd be layering trust on trust, wherein if they're willing to lie about one thing they're willing to lie about confirmation of that same thing (or not). Unless you're going to hire some independent auditor (that you still have to trust) it seems logically problematic.
Re: Signal Server code on GitHub is up to date again
#9Is there any mechanism to validate that the code running on Signal's servers is the same as on Github?
There's a counter-argument that there is still useful metadata a server can glean from its users, but it's certainly minimised with a good protocol... like the Signal protocol.
Re: Signal Server code on GitHub is up to date again
#10Is there any mechanism to validate that the code running on Signal's servers is the same as on Github?
Auditors
Trusted Enclaves (but then you trust Intel)
Signed chain of I/O with full semantics specified (blockchain style).