• DeckPacker@lemmy.world
    link
    fedilink
    English
    arrow-up
    5
    ·
    2 days ago

    Why would you not trust Signal?

    You don’t have to trust their server infrastructure, because the end to end encryption has been verified by countless experts (and all their client side code can be looked at by anyone).

    • WhyJiffie@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 day ago

      to be fair there is no way to verify the google play distributed app has been built from the published source code. there are also people arguing that the closed source google components built into it could work as a backdoor

      • DeckPacker@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        edit-2
        1 day ago

        You can build the app from source code though. Couldn’t you compare that to the Google Build?

        Also, you could use a fork like Molly, they removed all proprietary binary blobs and replaced them with FOSS alternatives. And it’s still fully compatible with Signal

        • WhyJiffie@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          2
          ·
          1 day ago

          only if the app is built reproducibly. I suspect the google libraries are likely minified/obfuscated by default though.

          Also, you could use a fork like Molly

          I do, but that’s only so much when the point of the app is communicating with other people