Hacker News new | past | comments | ask | show | jobs | submit login

The client has access to the address book and it is hard to verify what the client does in reality. I receive updates of the client every other day and who knows what it brings with it.



I don't think it is that hard to verify what the client does with your data. It is right there in the source.

> Since version 3.15.0 Signal for Android has supported reproducible builds.

https://github.com/signalapp/Signal-Android/blob/main/reprod...

I haven't tried to compare a local Android build to the published version myself, so can't directly confirm the accuracy of this document.

Either way, I agree that a released build can slip by unnoticed by most users. This is not a problem unique to Signal though.

At least with Signal you have the option to verify a build before updating. You can also build and run the entirely open source client yourself, which makes verification redundant.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: