• silence7@slrpnk.netOP
    link
    fedilink
    arrow-up
    79
    ·
    edit-2
    19 hours ago

    Signal makes it believable by providing source code and reproducible builds. It doesn’t rule out the possibility that they’ve done something clever with the random number generator, or have the app store you use give you a compromised app, or provide any protection against endpoint compromise, but it’s about as good as you can get.

    Third party apps derived from theirs, which explicitly promise to log all your messages to a server somewhere, like TeleMessage, are, for obvious reasons, far less trustworthy.

    • jaybone@lemmy.zip
      link
      fedilink
      English
      arrow-up
      4
      ·
      11 hours ago

      Question: how can they even claim it’s e2ee if they also claim to log all the messages? Or is the claim that they log the messages in encrypted form? In which case any client(s) with the only copy of the keys could delete them, making the logs useless.

      • merc@sh.itjust.works
        link
        fedilink
        arrow-up
        2
        arrow-down
        1
        ·
        36 minutes ago

        how can they even claim it’s e2ee if they also claim to log all the messages?

        Who are the various "they"s in that question?

        Signal claims that if you use the Signal app, it’s end-to-end encrypted. The Trump admin was using an unofficial Signal-compatible app TM SGNL which probably didn’t make those claims. And, Signal definitely never claimed that TM SGNL was end-to-end encrypted. In fact, it’s likely TeleMessage violated the copyrights and trademarks belonging to Signal with their app.

        But, in the end, the messages were still technically end-to-end encrypted. It’s just that as soon as the messages arrived at one of those ends, they were sent to TeleMessage who archived them unencrypted in AWS. It’s still end-to-end encrypted, it’s just that one of those ends is incredibly leaky.

      • tamman2000@lemm.ee
        link
        fedilink
        English
        arrow-up
        2
        ·
        edit-2
        5 hours ago

        I don’t know how they claim that would work. But it’s important to note that only telemessage makes that claim, not signal.

    • xor@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      6
      ·
      13 hours ago

      well they’ve also had great peer code reviews, and the reproducible builds lets you know they’re not putting a different version on the app store….