6 ms·
I wouldn't trust Signal for the sole fact that the USG promotes its use. Think CryptoAG and how hostile Swiss law is to data privacy. Kids seem to think just be
by jjones2 6y ago
I wouldn't trust Signal for the sole fact that the USG promotes its use. Think CryptoAG and how hostile Swiss law is to data privacy. Kids seem to think just because they were once known for banking secrecy doesn't mean they treat data the same way (they don't).
- Craighead 6y ago"Kids" know what works for USG will work for them
- junon 6y agoNevermind that Signal is entirely open source and has been openly audited several times. Lol.
- Frondo 6y agoAs others have pointed out, we users of Signal have no way of verifying that the code running on the server we connect to is the code they've released. We are very much trusting the Signal team to do what they're saying (not logging, not leaking) and to make no mistakes in doing it (not logging accidentally, not leaking accidentally). Which is in general a fair trade-off, but it is very much a trade-off, open audits notwithstanding.
- junon 6y agoWhere does Signal prevent you from using your own server? Spin up your own and use it if you'd like. https://github.com/signalapp/Signal-Server https://github.com/signalapp/Signal-Server
- NateEag 6y agoAs I pointed out elsewhere in the thread, Signal uses SGX to let clients confirm exactly what version of the contact discovery server software they're running against: https://signal.org/blog/private-contact-discovery/ https://signal.org/blog/private-contact-discovery/ It's not bulletproof by any means (https://signal.org/blog/private-contact-discovery/ https://signal.org/blog/private-contact-discovery/ goes into this, and also points out several features they've used SGX for since), but it's certainly something, and they're doing it.