this post was submitted on 09 Aug 2024
590 points (98.7% liked)

Technology

34385 readers
213 users here now

This is the official technology community of Lemmy.ml for all news related to creation and use of technology, and to facilitate civil, meaningful discussion around it.


Ask in DM before posting product reviews or ads. All such posts otherwise are subject to removal.


Rules:

1: All Lemmy rules apply

2: Do not post low effort posts

3: NEVER post naziped*gore stuff

4: Always post article URLs or their archived version URLs as sources, NOT screenshots. Help the blind users.

5: personal rants of Big Tech CEOs like Elon Musk are unwelcome (does not include posts about their companies affecting wide range of people)

6: no advertisement posts unless verified as legitimate and non-exploitative/non-consumerist

7: crypto related posts, unless essential, are disallowed

founded 5 years ago
MODERATORS
 

“We’re aware of reports that access to Signal has been blocked in some countries,” Signal says. If you are affected by the blocks, the company recommends turning on its censorship circumvention feature. (NetBlocks reports that this feature lets Signal “remain usable” in Russia.)

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 4 points 1 month ago (10 children)

And before lacked this and that. It keeps improving, contrast to Signal having the server code closed source for more than a year so the Signal devs could get a headstart and insider knowledge in their Signal-included crytpo coin grief.

How one can trust Signal after them showcasing what they truly stand for is mind blowing.

[–] [email protected] 3 points 1 month ago* (last edited 1 month ago) (3 children)

Signal having the server code closed source for more than a year so the Signal devs could get a headstart and insider knowledge

That argument makes absolutely no sense. This server-side code does almost nothing. The only task it really has is passing around encrypted packets between clients. All of the encryption is client-side, of course including metadata encryption. That's how end-to-end encryption works. The server code really doesn't matter. The Signal protocol, which is used for client-side, local, on-device end-to-end encryption has always been fully open, and it can be used by any app/platform.

How one can trust Signal after them showcasing what they truly stand for is mind blowing

It's very simple. The client is open source, and the encryption happens locally within the client application. You don't need to trust anything or anyone except for the code and mathematics, which are fully open, so you can verify them yourself.

It's mind-boggling how people attempt to spread so much misinformation while having absolutely no understanding of the topic their talking about.

[–] [email protected] 0 points 1 month ago (2 children)

That argument makes absolutely no sense. These server-side code does almost nothing. The only task it really has is passing around encrypted packets between clients.

So it knows about all metadata, plus registration with phone number, etc. got it.

The Signal protocol, which is used for client-side, local, on-device end-to-end encryption has always been fully open, and it can be used by any app/platform.

you conveniently leave out how you need to use the client built by Signal, with dependencies from Google Services and the like, and you can't use one built from the source they provide. Which at that point means they can introduce whatever they want in whichever version.

Decentralisation is the only safe way.

[–] [email protected] 0 points 1 month ago

You can use reproducible builds to verify that the provided clients are the result of the source code and you can also use alternative clients like Molly

load more comments (1 replies)
load more comments (1 replies)
load more comments (7 replies)