I trust it more than unencrypted SMS or Facebook Messenger. I trust it less than p2p chat over an encrypted network I control with layered defense in depth. Security is not a boolean.
Very true.
21–30 of 473 posts
I trust it more than unencrypted SMS or Facebook Messenger. I trust it less than p2p chat over an encrypted network I control with layered defense in depth. Security is not a boolean.
Very true.
This is true for just about every single piece of software that one downloads. But nice job deflecting it onto Signal to solve for you. Installing an APK by hand is not difficult either, you transfer it to your phone and open it. I don't see how Signal is doing any better or worse of a job from similar apps. Also, Signal's checksum verification is SHA-256 which I'd say is "good enough." It's also being served from an HTTPS webpage. Is there something missing here?
TL;DR he doesn’t trust Signal because he doesn’t trust the Android operating system, and something about federation. > No doubt these are non-trivial problems to solve. But I have personally been involved in open source projects which have collectively solved similarly difficult problems a thousand times over with a combined budget on the order of tens of thousands of dollars. Shut up and code then. I’ll personally r…
Is there a preference of Telegram over Signal or vice versa?
Secure messaging on android seems like an oxymoron.
But we have to trust that Moxie is running the server software he says he is. We have to trust that he isn’t writing down a list of people we’ve talked to, when, and how often. We have to trust not only that Moxie is trustworthy, but given that Open Whisper Systems is based in San Francisco we have to trust that he hasn’t received a national security letter, too (by the way, Signal doesn’t have a warrant canary). Mox…
use yalp store
> Packages on F-Droid are reviewed by a human being and are cryptographically signed
>The app has to update itself, using a similarly insecure mechanism. F-Droid handles updates and actually signs their packages
so are all android APKs. granted it's trust on first use: it accepts any signature for the first install, and only enforces the signature if you try to install an update.
>A checksum isn’t a signature, by the way - if your government- or workplace- or abusive-spouse-installed certificate authority gets in the way they can replace the APK and its checksum with whatever they want
this is probably the only legitimate concern, to use f-droid so you have a permanent anchor of trust (f-droid, rather than whatever CAs you have installed) for the first install. this isn't even that big of an issue when you can install using yalp store. google might be a rootkit or whatever, but at least you can be reasonably sure that the apks are the originals.
Is there a preference of Telegram over Signal or vice versa?
But we have to trust that Moxie is running the server software he says he is. We have to trust that he isn’t writing down a list of people we’ve talked to, when, and how often. We have to trust not only that Moxie is trustworthy, but given that Open Whisper Systems is based in San Francisco we have to trust that he hasn’t received a national security letter, too (by the way, Signal doesn’t have a warrant canary). Mox…
If Open Whisper Systems had received a national security letter requiring them to collect more information and keep it secret that they were doing so, how would you expect them to have responded to that subpoena?