7 ms·
Ask HN: What would convince you that a closed source messaging app is secure?
- deleted 1mo ago[deleted]
- Bender 1mo agoNothing. I barely trust open source after it's been in use for decades, reviewed by a myriad of pen-testers and battle hardened in the most hostile regions of the internet. I don't trust anything on a cell phone at all. That's just my take. Others may be more trusting.
- fsflover 1mo ago> I don't trust anything on a cell phone at all. Would you trust a phone running GNU/Linux with no proprietary drivers?
- Bender 1mo agoI would not. If the modem was ever open source hardware it would never be permitted to attach to the major networks. There's always a catch. There is just too much collusion between wireless carriers and governments, having built out one of the first GSM network in the US in the 90's. The capabilities were wild back then and I can only imagine all the undocumented capabilities now. I only learned about the capabilities having worked around a lot of drunk Swedish telco switch mainframe developers. Having said that, I would love to have a truly open source phone that I could load any bog standard Linux distro and all the drivers have been reviewed by Linus without him ever once feeling the urge to lift the middle finger. I would only be using it for non sensitive voice and text.
- fsflover 1mo ago> The capabilities were wild back then and I can only imagine all the undocumented capabilities now. I hope this can be eventually reverse-engineered. Pinephone's modem has some progress. My daily driver, Librem 5, is as close to such device as possible. It runs an FSF-endorsed OS and has hardware kill switches for wireless and mic/camera. Can't recommend it enough.
- Bender 1mo agoI've seriously considered the Librem. At the moment I have an ulefone armor with a really big battery and a very big bright LED flashlight for being in the wilderness though carrying a phone in the hills is not very practical. It's rugged but runs a carrier maintained version of Android. To have physical switches for wireless, mic and camera would be great. I am curious if you have run into any issues with RCS using a different OS and also curious if the Librem line will ever have a very rugged phone for extreme weather and with a really big battery for weirdo's like me.
- fsflover 1mo agoPurism is probably too small to create a rugged phone for extreme weather. I never used RCS, and it looks like it's not supported even on the original OS, https://docs.puri.sm/Hardware/Librem_5/Cellular_Networks/issues.html https://docs.puri.sm/Hardware/Librem_5/Cellular_Networks/iss.... > with a really big battery Instead of a really big battery, I take a couple of backup batteries with me. Replacing the battery takes 30 seconds.
- handedness 1mo ago> Can't recommend it enough. See, I think you can.
- fsflover 1mo agoI'm glad I now have a personal HN hater coming to every comment of mine with a snark or (far-fetched) dismissal. Makes me feel important (not really, just funny).
- handedness 1mo agoIt's amazing what endless shilling can accomplish!
- handedness 1mo agoWhen you put in the effort to make a substantive comment, and forego the empty one-liners teaching us nothing, nobody is happier than I am to not respond.
- Brandon-Coll 1mo agoFair, but open source also automatically does not mean more trustworthy. What matters is what can actually be independently verified about the software you are running. what is you take on this? also I believe the potent security features must be there in messengers which name them secure and private
- nacozarina 1mo agoCombo of reputation & provenance. Someone widely respected as a super-competent programmer and known to be somewhat of a self-directed loner. If Fabrice Bellard suddenly decided secure messaging was what he was committed to doing, I wouldn’t care if he did it closed-source.
- Brandon-Coll 1mo agoThat is and can be one way to establish trust, but most users won't know the people behind the software. do you think trust can be earned through things like security architecture, independent validation, audits, and collecting as little user data as possible.
- deleted 1mo ago[deleted]
- JohnFen 1mo agoIt's extremely hard to trust, and such a claim always boils down to "trust me".
- Brandon-Coll 1mo agoso if the closed source platforms are independently audited by DEKRA and verified by NIST CAVP cryptography, still hard to trust?