this post was submitted on 28 Jul 2024
259 points (100.0% liked)

Technology

70249 readers
3468 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 4 points 9 months ago (2 children)

Especially with Signal being open source. What stops the official Signal company from advertising another fork?

[–] [email protected] 4 points 9 months ago (2 children)

The server software is not open source.

[–] [email protected] 15 points 9 months ago (2 children)
[–] [email protected] 9 points 9 months ago (2 children)

There's a grain of truth in the claim: We don't know for sure if the original open source version is actually running on the server.

[–] [email protected] 11 points 9 months ago (1 children)

Isn't that true of all server side FOSS?

[–] [email protected] 5 points 9 months ago* (last edited 9 months ago) (1 children)

Yes. We just have to trust them. Or selfhost, which I'm doing with almost everything.

[–] [email protected] 4 points 9 months ago

They've said that they release the source code after it's running in production:

sorry the source for one of our services was so far behind. We often don't push source until we release things, and there were a few overlapping releases that happened in that period which made it awkward to push at any moment and put us behind. Additionally, we've seen a large increase in spam, and a reluctance to immediately publish the exact anti-spam measures we were responding with to a place where spammers could immediately see them combined with the above to cause this extreme delay.

https://github.com/signalapp/Signal-Android/issues/11101#issuecomment-815400676

[–] [email protected] 6 points 9 months ago

In that case: They started publishing code AGAIN.

The server soft has been available, then not, and apparently now again.

[–] [email protected] 4 points 9 months ago (1 children)

That'd be irrelevant, because as long as only the clients hold the keys (which we can verify, as those are not only open source but also are under our control, meaning we can check that the upstream open source version is installed and no private keys are being exchanged) there's no way anyone can read the messages, except the owner of the private key.

[–] [email protected] 2 points 9 months ago

Messages - yes, but there is also metadata. When ALL communication goes through the same servers, it becomes kind of a problem.

[–] [email protected] 2 points 9 months ago

"Gruyere Signal"