So I have to ask myself: What happens if Signal has financial issues?
edit: Signal is open-source and non-profit as commenters pointed out. That's indeed advantageous.
So I have to ask myself: What happens if Signal has financial issues?
edit: Signal is open-source and non-profit as commenters pointed out. That's indeed advantageous.
Signal not only encrypts messages (Whatsapp does as well), but also seem to make sure there is as little meta data available as possible. This should make it less interesting for eg. Facebook to buy them.
This data is there at any rate however confederated chat apps can use different servers (so data is not congregated) and you can also change accounts easily (it's harder to change phone number).
Similar philosophy to Signal of trying to really get usability right (looking at you, Element). Though still early in alpha development, wouldn't trust current alpha builds to be reliable.
But yeah, as long as they own the servers I am sure they could puzzle it together if they wanted.
There have been a number of independent security audits over the years, which are easy to find. WhatsApp code was never open, even pre-Facebook.
On the client side I find their interest on self-updating problematic (since they may silently push updates to specific users), but at least you do have the option to remove it.
That said, I (like others) am a bit concerned about the lack of updates to Signal-Server (https://github.com/signalapp/Signal-Server/commits/master). Commits seemed to suddenly stop April last year, and I'd be very surprised if the actual Signal Server that's running in production hasn't been updated over such a long period. Would be very happy to be proven wrong here, or to be pointed in the direction of anything that might explain the lack of activity.
At the end of the day they literally control the only in-pipe and the only out-pipe and can measure whatever the heck they want from it. Including from which address the message came from.
And I'm curious about how infrequent that is, considering that to use sealed sender you actually have to login 'frequently' to their server (to update the keys you use), and I couldn't see how much frequent that is (or even whether it is a server-initiated which would defeat the purpose).
It would need to be a month or so to have a reasonable benefit. But I don't see why that's not doable.
https://forum.f-droid.org/t/signal-wickr-on-f-droid-2021/122...