It wasn’t copied from Signal — at the protocol level, it is Signal:
It wasn’t copied from Signal — at the protocol level, it is Signal:
That prior technology, by the way, PGP, is not and was never universally hated. Many businesses continue to use PGP today to exchange encrypted communications with suppliers and customers. It's mostly file transfers, but some businesses even support secure email via PGP, and it's been integrated into a modern secure email product from a Swiss company, Proton, targeted at both consumers and businesses.
Also false. XMPP OTR existed long prior.
Quite the opposite, they start with techniques they work on the binary and only use the source (if available) as a helpful reference. Hiding back doors in source has a long and storied history so relying on it to audit security has long been out of favor.
It could be very well obfuscated.
Second: when you read source code, do you start at the lexicographic first .c file and just read downwards? No? Neither do reversers.
I've reverse engineered file types. But not actual code.
On the other hand, maybe your binary can be decompiled to source code (e.g. CFR can decompile java classes, I've used that a bit but haven't checked if that's useful for Android apps).
Maybe this was bad advice, this approach is like trying to learn a spoken language by listening to a recording and looking up each word at a time. Probably it'd be better to get a deep understanding of how CPUs work in general, I can recommend the book Computer Organization and Design by Hennessy and Patterson for this. I agree with the other commenter that 15 years is more realistic so maybe just start by getting a 4 year degree in CompSci (and that book will probably be required reading).
All in all with 15yrs of training you can start the task :D
What you say can be true if source is readable and well written and you have somehow a guarantee that source is not modified before publishing the app. Or if you just are inexperienced with auditing the app other than reading the code (I know I am).
If we're interested in whether WhatsApp's developers have implemented the Signal protocol in good faith, because we suspect they have not (we suspect they've put in backdoors at the behest of bad governments), then having the source available (and reproducible builds to use) allows us to check that more easily than analysis on the binary's behavior.
This is because the primary way the duplicitous maintainers would do this is in their own source. It's possible (and for three letter agencies probably common and desirable) to deliberately introduce bugs in dependencies that provide the desired behavior in some end product, but it probably shouldn't be our base case. Our base case should be: you swear your code implements the Signal protocol without backdoors...ok, great, you show us the code.
Does Signal itself even have reproducible builds?
They are fully entitled to do that of course, as it is their system. But that makes it far less useful for hobbyists.
Like, prove to me Facebook isn't logging and storing every single cryptographic key generated in that entire protocol. Oh, you can't because the entire app is closed source? And you just blindly trust that Facebook is doing the right thing and not decrypting every message to scour it for every bit of information possible?
lol.