☆ Yσɠƚԋσʂ ☆@lemmy.ml to Privacy@lemmy.mlEnglish · 2 days agoTelegram Hands U.S. Authorities Data on Thousands of Userswww.404media.coexternal-linkmessage-square103fedilinkarrow-up196arrow-down11cross-posted to: world@lemmy.worldtechnology@beehaw.org
arrow-up195arrow-down1external-linkTelegram Hands U.S. Authorities Data on Thousands of Userswww.404media.co☆ Yσɠƚԋσʂ ☆@lemmy.ml to Privacy@lemmy.mlEnglish · 2 days agomessage-square103fedilinkcross-posted to: world@lemmy.worldtechnology@beehaw.org
minus-squareKairos@lemmy.todaylinkfedilinkarrow-up2arrow-down2·1 day agoOkay. You tell me what the double ratchet is, since you’re so smart.
minus-squaredavel [he/him]@lemmy.mllinkfedilinkEnglisharrow-up3arrow-down2·1 day agoThe double ratchet algo is irrelevant if the app is doing something else altogether.
minus-squareKairos@lemmy.todaylinkfedilinkarrow-up2arrow-down2·1 day agoCompiling the app is irrelevant if I don’t read the source.
minus-square☆ Yσɠƚԋσʂ ☆@lemmy.mlOPlinkfedilinkarrow-up3arrow-down3·1 day agoThat’s nonsense, because many different people read the source and audit open source software. While it’s certainly possible to sneak malicious code in, the trust doesn’t depend on each single individual auditing it. It’s a collective effort.
minus-squarePup Biru@aussie.zonelinkfedilinkEnglisharrow-up1·24 hours agookay, but reproducible builds solve the rest of that problem https://signal.org/blog/reproducible-android/
minus-square☆ Yσɠƚԋσʂ ☆@lemmy.mlOPlinkfedilinkarrow-up2·20 hours agoYeah, now that they finally have reproducible builds, at least you can trust that the client is doing what it says it’s doing.
Okay. You tell me what the double ratchet is, since you’re so smart.
The double ratchet algo is irrelevant if the app is doing something else altogether.
Compiling the app is irrelevant if I don’t read the source.
That’s nonsense, because many different people read the source and audit open source software. While it’s certainly possible to sneak malicious code in, the trust doesn’t depend on each single individual auditing it. It’s a collective effort.
okay, but reproducible builds solve the rest of that problem
https://signal.org/blog/reproducible-android/
Yeah, now that they finally have reproducible builds, at least you can trust that the client is doing what it says it’s doing.