Earlier quoted context omitted.
> do you know whether the software you got from the App Store is the software that's on Github? Yes: https://whispersystems.org/blog/reproducible-android/
... minus the libraries in native code which also are considerably harder to reverse-engineer than the java parts. Also, unless you're suspicious and actually check, you could be served a special version by the App Store that was compiled only for you and contains the required add-a-key-but-dont-show-a-popup feature. I'm not saying that Signal and/or Google are shipping a backdoor. I'm saying that we have to trust th…
> I'm saying that we have to trust them that they don't.
This applies to anything. It is not feasible to build and/or check all software and hardware by yourself.