Live data from Hacker News

European Court of Human Rights bans weakening of secure end-to-end encryption

eureporter.co

271–273 of 273 posts

Re: European Court of Human Rights bans weakening of secure end-to-end encryption

#271
post #269
post #250

Earlier quoted context omitted.

I am very suspicious of Signal, for not not being on f-droid, but being on play store. I'm sure the protocol is fine and all, but playstore can easily be used to compromise everything anyway. Also I've read many times Bruce Schneier claim that Signal is the most secure communication system that exists, and Whatsapp is the 2nd best, because it (allegedly, but we don't know) uses the same protocol.

Do you think F-Droid is more resilient to malicious influence than Google's Play Store? I haven't looked deeply into how F-Droid is currently operating, so maybe I'm off here, but isn't it just all on a server run by some random guy in his free time? I love what F-Droid is doing, and I think it has a bright future, but in its current state I would never trust it on any of my devices that I use for anything important.…

Using libsignal doesn't mean that there is no API to enable a side channel :)

I think that google and apple would just comply and do whatever they are told, while the f-droid guy needs to be hacked and might notice he got hacked, so in that sense it's safer.

Re: European Court of Human Rights bans weakening of secure end-to-end encryption

#272
post #250

Earlier quoted context omitted.

I am very suspicious of Signal, for not not being on f-droid, but being on play store. I'm sure the protocol is fine and all, but playstore can easily be used to compromise everything anyway. Also I've read many times Bruce Schneier claim that Signal is the most secure communication system that exists, and Whatsapp is the 2nd best, because it (allegedly, but we don't know) uses the same protocol.

Them not being on F-Droid is justifiable because F-Droid app IS less secure than alternatives. It does not use modern Android session installer, which is problematic in many different ways. Granted, there are third party F-Droid apps like Droidify that fix these issues.

How is it less secure than the play store?

Re: European Court of Human Rights bans weakening of secure end-to-end encryption

#273
post #53

Earlier quoted context omitted.

I'm quite sure they can use the app store to push a targeted update just to some.

No need, push an update to all that only affects certain users. But if anyone ever de-obfuscates that, your reputation is gone.

If you push only to some it's less likely to ever be detected.
Post reply on HN