What if someone changed the open source before shipping it to the app store?
What if someone changed the open source before shipping it to the app store?
I have a phone with Signal on it. Tell me what I should do to verify it's running the open source Signal code.
https://play.google.com/store/apps/details?id=com.funnycat.v...
> the Signal Android codebase includes some native shared libraries that we employ for voice calls (WebRTC, etc). At the time this native code was added, there was no Gradle NDK support yet, so the shared libraries aren’t compiled with the project build.
Also, assuming you trust the client, how to tell if the Signal server is running the published code, especially given Signal's track record of (not) publishing its source code?
https://linuxreviews.org/Signal_Appears_To_Have_Abandoned_Th...
Otherwise somewhere in the chain you are relying on binaries of unknown provenance.
If someone with skills X (where depending on your knowledge and precautions, X can range from script kiddie to nation state) is after you specifically, you can only make their job harder, but unless you are very serious about security, you’ll probably get pwned.
If you want general security, you can probably take it as given that someone checked the Signal build to be the one that the source is available for, and that no one intercepted just your download. But you still have to take some parts on faith, always, unless you build your own CPU and continue from there.