I think it's time we just admitted that everything we type/tap/say into any device, regardless of how it's being wrapped up in transit, is absolutely and irrepairably insecure and we're not going to be able to fix that anytime soon.
Even with really smart crypto or some slick app; what makes you think that your messages aren't just being read by your os? Would you really notice? Why would you assume that the api this app talks to is trustworthy? There's no way to even tell if the code for the client on your device is the same as what's in that repo, as if it would make any kind of difference anyway since we can just load code from anywhere at runtime and you'd probably not even notice.
This whole thing is a fucking stageshow, I can only assume we're here to create an illusion that we still have any kind of security. Why? Is it to get some low hanging fruit/tech amateurs who will trust it and expose themselves? I don't know. But, HN, I don't know why WE aren't admitting this to ourselves or why we defend such obvious ruses.
Well, maybe some of you have signal stock I guess.
It's over, we lost, we have no security, we will probably never be able to reverse that situation, things are getting worse rapidly, we can't even know what any of our devices are really doing anymore (even the switches in your dc, the firmware on the UPS's, whatever), and apps like signal are obviously, to me, impossible to trust and I don't know why that's not obvious to anyone who has spent a moment looking at our situation..
Argh.