Comment on Lawsuit Alleges That WhatsApp Has No End-to-End Encryption

<- View Parent
Tanoh@lemmy.world ⁨5⁩ ⁨days⁩ ago

And Signal is open source so, if it did anything weird with private keys, everyone would know

Well, no. At least not by default as you are running a compiled version of it. Someone could inject code you don’t know anything about before compilation that for example leaked your keys.

One way to be more confident no one has, would be to have predictable builds that you can recreate and then compare the file fingerprints. But I do not think that is possible, at least on android, as google holds they signature keys to apps.

source
Sort:hotnewtop