Only a bit of transport level integrity. But it doesn't make your average hosting provider into a high assurance one or its servers, OSes, software stacks, etc. Quite known problem since the cryptocurrency era.
Which is maybe why Moxie is encouraging people to rely on Google Play Store.
If you are so concerned about state-level actors that play store is untenable to you, signal and android on commodity hardware are probably not the solutions you want anyways.
It seems pretty odd to me to distrust someone because they aren't using the platform that you'd like them to use. Aren't there other issues with f-droid? You have to root your device to run it, allow third party code. Those are all security concerns too. It was posted elsewhere but here's Moxie's take: https://github.com/signalapp/Signal-Android/issues/127#issue...
> It seems pretty odd to me to distrust someone because they ... ... are using a platform "you" don't trust. Really? That's not really odd. At least, it's not odd, if that usage and what it entails is the denominating part of the persona in this question.
Whats odd is calling a application "not secure" because it uses the platform's software distribution channel.
Here's a thought. If you are so concerned about the NSA that you think Google's cloud is a problem, why are you running the OS developed by Google?
Is there a preference of Telegram over Signal or vice versa?
Telegram doesn't have end-to-end encryption by default (only in secret chats). That's all you need to understand to know that it's an inferior product in comparison to Signal.
It's also the case you can't use Telegram's end-to-end encryption on desktop clients at all.
> Truly secure systems don’t require trust. Security is something which only makes sense in relation to an attacker model. Only after you specified that, then we can discuss if something is secure or not. Signal is not secure if the NSA is after you. Signal is secure if your Chinese competitor is after your business data. Signal is secure if you are a journalist in Turkey.
Remember that OTR, Cryptocat and PGP were secure enough when Snowden was agreeing about handing data to Greenwald and Poitras. So while Signal isn't secure if you're NSA's target, it might be secure enough to protect you from passive threat scanning.
But in the linked post he does not explain, why he does not maintain a F-Droid repository for people who do not trust google, nor why the original Signal Client does not connect to Signal Forks, even if they use everything the same. Security reasons? Ordinary smartphones are full of rootkits anyways, so someone using a forked Signal version probably is better of anyway, as he knows a bit more what he is doing. So the…
"why he does not maintain a F-Droid repository for people who do not trust google" Are you paying him to do that? No? Well, there you go. It's more work, for what appears to be very little benefit.
I would pay a share, and I'm sure others would too. Unless he has set a price and there were no takers, that argument is fallacious.
People should just know by now, if you need to communicate something in private, you should just never use any electronic device that uses public networks. All of these "secure" tools that are being used must be understood in that context. They are "secure" against honest people. What I mean by that is that it's a lot like your home or apartment. Sure, you should lock your door and turn on your alarm system when you…
People still need to communicate with their peers in insecure networks. Now you need to compare the nitty gritty details and choose the most secure one for your needs. If you need content protection to keep dick picks out of NSA office circulation, Signal is probably the best. For metadata-free chat, Ricochet and Briar are currently the top duo.
I agree that Tox is better but at the same time I know people who truly need to stay hidden and they use Signal on a burner phone with a cash sim-card. That way it doesn't matter which medium the messages are transmitted over because it still can't be traced back to them. And as far as I know the encryption is solid. Unlike some other alternatives like Wickr Signal actually open sources their app and their communicat…
Until Tox defaults it's communication through Tor, it doesn't offer any notable differences. Sure, there is no central server, but intelligence agencies can see who you talk to without compromising server just by looking at the destination IP address of packets. Tox suffers from same MITM problems if the ToxID is changed e.g. on Twitter page of your contact, the same way the author of the article claims the "checksum" of Signal's APK can be changed by NSA, your employer or angry spouse.
Moxie doesn't address the concerns of conctributors, either. Here's one from this very comment thread: https://news.ycombinator.com/item?id=17724893 Others have emailed me as well, thanking me for putting to words what they felt afraid to for fear of retribution from "Moxie and his religious following" (direct quote).
google, facebook, whats app, microsoft. Basically the companies that pay for signal end to end encryption in their chat apps. There are, I'm sure, apps that are better, and that's never been moxie's goal. He's said it over and over that he'd rather have encryption for the masses than the perfect messaging app. It seems disingenuous to assume that he's acting in bad faith when he's clearly doing exactly what he said h…
Pushing an app out to F-Droid is trivial. There is literally no defense for only using Google Play and unsigned binaries on his own website.
I believe that to use the same app, he requires google play? Am i missing something? You can export the app yourself from google play and it doesn't run unless you have google play installed.