Ever since that, I don't think you should consider Signal's server "open source" at all. They've shown they'll conceal, diverge and cover up for their own enrichment. What will they do when they're threatened? Cave.
>Last commit 7 Days ago
>AGPL-3.0 License
That's the present
If there's a single piece of closed source code running on the servers, it ceases to be open source.
Yeah no that's not the definition of opensource, if my opensource mailserver has a closed source spam-scanner, my mail server is still opensource - the spam-scanner
phone_home_to_nsa(metadata, ip_address, sender, recipient);
Are you still comfortable with this 'open source' project?
Maybe there's some sort of cryptographic attestation out there which could fulfil such purposes but quite sure it's not that practical.
There are a few reasons why I would prefer them to provide source code that they claim is running in the service due to the metadata issue:
a) if it's actually running there, people can find simple bugs in it that could allow that metadata to be stored or revealed by accident,
b) if it's not actually running there, but something very close is (i.e. that code with small amount of patches), then the advantage above still applies and if those patches come to light, they can be easily evaluated for intent and effect,
c) if they're running something completely different (which would be very weird), it'd be noticeable and it would be an obvious lie once exposed.