Feel free to read more implementation details in our WhitePaper - https://sliksafe.com/whitepaper.pdf
Feel free to read more implementation details in our WhitePaper - https://sliksafe.com/whitepaper.pdf
(A malicious employee could do such a thing, or you could be legally obligated to do so in order to continue operating in certain jurisdictions.)
How do you prevent yourself from serving a compromised iOS/Android/Mac/Windows app? Same answer.
For app store based distribution, the developers can set up a deterministic build, and end users can verify the checksum of the package matches the developer’s published source code (signal supports this).
Additionally, a regular app can be signed by a key from the developers that you can verify. With a web app you don't even know if it comes from the developers or if you're being MITM-ed because someone managed to get a SSL certificate for your domain. The certificate isn't the only angle of attack either, your CDN or hosting provider might be hacked. Yes the CDN that hosts the regular app can also be hacked, but that will only work against brand new users, because existing users can already know the signing key and the hacked binary won't have the correct signature.