Granted, the part

The globally recommended app by privacy and security experts, Signal, is now being downloaded massively and tops the Danish Google Play Store

is a little ironic, but you gotta push this winning tide and then work from that.

  • plyth@feddit.org
    link
    fedilink
    English
    arrow-up
    1
    ·
    2 days ago

    it could detect that the server is not running the published source code.

    How? The clients can only notice if the API works as specified. The server can constantly be replaced without anybody noticing.

    is at least as safe as any other app, at least the ones of comparable usability. Or are you’re just saying we’re all lost anyway

    So you know the problems of the servers.

    • Vincent@feddit.nl
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 day ago

      How? The clients can only notice if the API works as specified. The server can constantly be replaced without anybody noticing.

      See the link I posted before about the secure enclave. (Note that I could’ve been clearer before: it’s not specifically the Signal client app that needs to detect server tampering; any software could.)

      So you know the problems of the servers.

      So what are you saying? Don’t use anything that has a server? (To be fair, I think it’s a good idea to have pure peer-to-peer apps installed as well, but for most situations that would still just come down to “do not communicate digitally at all”.)

      • plyth@feddit.org
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 day ago

        See the link I posted before

        Ok, that’s good.

        So what are you saying?

        That there is risk to rely on the server. It’s unavoidable but should not be neglected.