Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Any modifications for the app binaries and protocols would be quickly noticed

Signal doesn't support reproducible builds, does it?



There are reproducible builds on android, and reproducible builds are simply not possible on iOS due to Apple's own decisions.


It’s entirely possible to inspect a binary even if the build isn’t reproducible.

https://news.ycombinator.com/item?id=41361609


"Entirely possible" is a misleading argument.

I don't understand why Signal is not pursuing the reproducible builds. It looks suspicious. Verification of a binary takes a huge effort and can only be done by knowledgeable people. Case in point: nobody noticed or cared about the lack of undisclosed binary updates of Signal without released sources.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: