• 12 Posts
  • 2.24K Comments
Joined 3 years ago
cake
Cake day: July 7th, 2023

help-circle












  • The clients (apps) enforce key symmetry for your own keys, server identity, and the exchanged with the other person part of a conversation. Constantly. There is no way to MITM that.

    The clients are open source, and audited regularly, and yes, builds are binary reproduceable and fingerprinted on release.

    That’s not to say someone can’t build a malicious copy that does dumb stuff and put it in your phone to replace the other copy, but the server would catch and reject it if it’s fingerprints don’t match the previously known good copy, or a public version.

    Now you’re just coming up with weird things to justify the paranoia. None of this has anything to do with Signal itself, which is as secure as it gets.