Signal and iMessage both don't guarantee true privacy as we can't see the servers.
Signal and iMessage both don't guarantee true privacy as we can't see the servers.
For common users the question is if you trust the server operator, and if not, to consider your communications insecure. What they do about that is up to them. And it is up to these providers to earn trust.
And there are no services that do that. Since that doesn't seem to be possible. Open sourcing the backend doesn't help here since you still have to blindly trust the server operators.
I mean when a company does that, it makes it pretty clear that they do want to monitor your location, making it annoying for you to turn it on and off.
And even then it's only 4 taps. Which is 1 more tap than what's involved in changing WiFi networks something a lot of people do.
I don't need to read Signal code to have confidence in its working.
Not sure about that. I think even if a power user were to say "this is safe", you still have a boatload of integrity problems with the software.
-How do we know the power users can be trusted?
-Even if they can, what guarantee do we have that the service provider we use is using the same open source code that the power user validated?
-Etc, etc, etc. Basically, a lot of trust issues.
I agree with asadlionpk, open source can generally only be proven to help power users in a trustless environment. And where security is concerned, we cannot ascribe the "safe" attribute to any system where that safety cannot be proven.
I roll an OwnCloud server for me and my family, and I know that I'm not invading their privacy, but I could very easily do so and not leave a trace of my having done it even that a pro user could find, let alone a layman. To say that Apple is less trustworthy than a given power user solely because they use closed source is ridiculous, there is zero correlation there.
Power users can make sure the code they're running is safe for them. There's no guarantee that Signal for example is running the same code they release to others.
What do you define as true privacy? Why isn't other privacy "true"?
What do you mean by "see the servers"? Surely you can see them as computers at the other end of a TCP connection, and the server cannot read the cleartext of an E2E encrypted message.