Live data from Hacker News

About backdoors in crypto messengers

blogs.fsfe.org

1–10 of 71 posts

Re: About backdoors in crypto messengers

#4
If you're considering Google an adversary, perhaps you shouldn't use stock Android, or any of their software.

If you're considering Google an adversary, and use a version of Android without Google support, you can't use Signal anyway.

Re: About backdoors in crypto messengers

#8
The backdoor referred to can be applied to any Android app that uses Google Maps. Also mentioned is that using the built-in Google keyboard is a vulnerability, because in theory it gives Google the ability to keylog you.

I supposed this boils down to knowing your adversaries. If you number Google amongst that list, life is going to be really difficult - no matter who you are.

Re: About backdoors in crypto messengers

#9

It seems that if you really want proper secure channel you need to write one yourself. Anything out there is subject to being compromised. Is there open source alternative for Signal?

You don't have to look far. The actual Signal client source is licensed under GPLv3.

Edit: And server code under AGPLv3.

Re: About backdoors in crypto messengers

#10
post #4

If you're considering Google an adversary, perhaps you shouldn't use stock Android, or any of their software. If you're considering Google an adversary, and use a version of Android without Google support, you can't use Signal anyway.

Actually, it is possible to use Signal on Android without Google using the opensource microG and Xposed framework (setup is a bit involved...but you can google that :P for a guide).
Post reply on HN