Earlier quoted context omitted.
> Signal has open clients with reproducible builds. Not really. First of all, there is only one Signal client allowed to connect to Signal’s servers. And in the real world, the vast majority of Signal uses are getting their APK for that app from the Google Play store (the Signal team has said that they prefer you to use the Play store as well, instead of direct-downloading an APK from their website which they offer o…
The point isn't to build your own and use it; it's to verify that the binary in the app store matches the source they published.
Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA
241–243 of 243 posts
Do you personally do that with every release (which happens every few weeks or so)? Do you know anyone who does that who is trustworthy? If not, it's a fairly useless form of protection.
Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA
#242Earlier quoted context omitted.
But nobody actually does that.
Not manually, perhaps. But automated integrity checks of reproducible builds are trivial to write.
Have you personally done that? Do you know of anyone who is doing that and publicly tracks said verification? It doesn't matter how trivial it would be to verify if nobody is actually doing the verification (not to mention you'd actually want many people doing it and publicly posting their verification, as well as you checking that your hash matches everyone else's before installing the APK -- and there is no automated setup for doing that on Android.)
Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA
#243Earlier quoted context omitted.
Not manually, perhaps. But automated integrity checks of reproducible builds are trivial to write.
Have you personally done that? Do you know of anyone who is doing that and publicly tracks said verification? It doesn't matter how trivial it would be to verify if nobody is actually doing the verification (not to mention you'd actually want many people doing it and publicly posting their verification, as well as you checking that your hash matches everyone else's before installing the APK -- and there is no automat…
I don't think any significant number of people do it. I don't use Signal specifically, but I don't even know that there is a way for me to actually do it and then track whether that matches the version the iOS app store loaded on my phone, at least not without jailbreaking the phone.