• lattrommi
    link
    fedilink
    English
    arrow-up
    13
    arrow-down
    5
    ·
    2 years ago

    This was first published in 2021. There are some interesting points made.

    https://dessalines.github.io/essays/why_not_signal.html

    It has had a few updates since, then but I cannot vouch for its accuracy.

    It doesn’t cover audits per sé, but I feel there is important information that is tangentially related, since security audits become kind of moot if some of the items mentioned are true (i.e. CIA funding and US govt. tactics).

    Full disclosure, I still use Signal for a family group chat. I have very little economic value, thus my threat model is minimal. It mentions cats several times. I neither have cats, nor interact with them frequently enough to warrant their inclusion in a threat model.

  • warmaster@lemmy.world
    link
    fedilink
    arrow-up
    14
    arrow-down
    7
    ·
    2 years ago

    You can’t trust them, being a centralized service based in a country where things could go way lore south anytime.

  • foremanguy
    link
    fedilink
    arrow-up
    5
    ·
    2 years ago

    As I seen in other comment I think that the protocol is audited not really the app and servers In comparison SimpleX is audited pretty regularly

    • adbenitezOP
      link
      fedilink
      arrow-up
      1
      ·
      2 years ago

      thanks, I think I know that one, but yeah as you said it is not a real security audit and the person itself said so

  • Melody Fwygon@lemmy.one
    link
    fedilink
    English
    arrow-up
    5
    arrow-down
    1
    ·
    2 years ago

    Lack of detailed audits…only in this case specifically…does not imply lack of security and/or privacy.

    The protocol that Signal uses, which is in fact firmly audited with no major problematic findings, plus the fact the client is OSS is generally enough to lower any concerns.

    The server side software in production for Signal.org is not OSS. It will not be. You are required to trust the server to use Signal; because the protocol and the client renders it factually impossible for the server to spy on your messages. The server cannot read messages; or even connect who is messaging who if the correct client settings are used. (Sealed Sender).

    Non-OS stats software in general is not automatically lacking in privacy or security, particularly not in this case where the affected software does interact only with software that is verifiably open-source and trustworthy in general due to the protocols and how they are implemented correctly in a verifiable manner.

    • MonkderVierte
      link
      fedilink
      arrow-up
      2
      arrow-down
      3
      ·
      2 years ago

      Non-OS stats software in general is not automatically lacking in privacy or security

      Sure is. It’s only that in this case you are sure that your messages are sufficiently protected, so you can send them over a untrusted service.

    • adbenitezOP
      link
      fedilink
      arrow-up
      4
      ·
      2 years ago

      does that one has security audits? thanks in advance

            • Squizzy@lemmy.world
              link
              fedilink
              arrow-up
              1
              ·
              2 years ago

              Exactly the issue, same as always. Signal got rid of sms because it was insecure but enable reply in notifications by default.