How do you know if the Signal client running on your phone right now doesn't include a backdoor? Sure it's open source. But how do you know how it was compiled? What if someone changed the open source before shipping it to the app store?
Global Encryption Day: Demand End-to-End Encryption in DMs
11–20 of 78 posts
Re: Global Encryption Day: Demand End-to-End Encryption in DMs
#12How do you know if the Signal client running on your phone right now doesn't include a backdoor? Sure it's open source. But how do you know how it was compiled? What if someone changed the open source before shipping it to the app store?
Re: Global Encryption Day: Demand End-to-End Encryption in DMs
#13Kind of meaningless if you can't trust the software running on your device though, since it could be scanning locally or relaying to remote services.
It is fallacious because you'll never get there if you're not allowed to make incremental advances.
Re: Global Encryption Day: Demand End-to-End Encryption in DMs
#14Re: Global Encryption Day: Demand End-to-End Encryption in DMs
#15End to end encryption is critically important and no messaging standard should exist that doesn't include it.
Re: Global Encryption Day: Demand End-to-End Encryption in DMs
#16Kind of meaningless if you can't trust the software running on your device though, since it could be scanning locally or relaying to remote services.
So run free software?
It literally isn't possible for an ordinary person to audit all code.
At some point you have to blindly trust.
Re: Global Encryption Day: Demand End-to-End Encryption in DMs
#17Remember when Zoom claimed that meetings were E2EE yet you could join the meeting by phone and no one batted an eye for at least one or two years? Noticed how no regular person cares when the "security code" of a chat partner changes in WhatsApp or Signal? Not to mention no regular person uses self-compiled apps for that, even if it were possible. E2EE is close to becoming a cargo cult, because done properly key mana…
Re: Global Encryption Day: Demand End-to-End Encryption in DMs
#18How do you know if the Signal client running on your phone right now doesn't include a backdoor? Sure it's open source. But how do you know how it was compiled? What if someone changed the open source before shipping it to the app store?
This is called "Reproducible Builds". https://signal.org/blog/reproducible-android/
I have a phone with Signal on it. Tell me what I should do to verify it's running the open source Signal code.
Re: Global Encryption Day: Demand End-to-End Encryption in DMs
#19Remember when Zoom claimed that meetings were E2EE yet you could join the meeting by phone and no one batted an eye for at least one or two years? Noticed how no regular person cares when the "security code" of a chat partner changes in WhatsApp or Signal? Not to mention no regular person uses self-compiled apps for that, even if it were possible. E2EE is close to becoming a cargo cult, because done properly key mana…
So what you're saying is, we can just put a green lock in the UI and call it a day.
The outrage "own your private keys or bust!" is much easier tho.
Re: Global Encryption Day: Demand End-to-End Encryption in DMs
#20Earlier quoted context omitted.
So run free software?
Like signal that still refuses to put their client on fdroid?
(Yes, F-Droid availability is a very good cutoff, I agree.)