Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> But note that Signal doesn't know your number

Courts can compel them to keep these records, and require them to not disclose to their customers that they are doing so.



I'm no legal expert, but that seems difficult for a court to do. They're not legislative (or, not supposed to be). And I'm certain the ACLU would fight that tooth and nail.

Signal was subpoenaed in court, and told to give up information[0] on certain customers. They replied the only information they had was the time the account was created and the date of the last connection. Admittedly, this was over 5 years ago. They fought to get these court records released.

[0]: https://arstechnica.com/tech-policy/2016/10/fbi-demands-sign...


My understanding is that the phone number is never even sent to Signal in the first place. So doing so would result in a git commit.


Is there an audit trail showing that the compiled binary available in the App store is the same one you build from source?


Sadly, no.

There’s still some “trust” required in both Whispersystems to not backdoor updates, as well as Apple and Google to not backdoor the distributed apps after Whispersystems submit updates for publication.

There is though, some ability for skilled enough people to “trust but verify” by reversing the app bundles after publication. I believe (but not for any good evidence based reason) that there are “enough eyeballs” interested in Signal that _hopefully_ if a backdoored app update ever appears the white hats will raise the alarm quickly (I have no doubt the black hats will sell the details to NSO/GreyKey just as quickly...)


You are able to compile from source though...


Assuming the published app matches the published source.


At least Apple have demonstrated pushing back on a court order requiring them to fundamentally break their product’s advertised security to comply with such an order.

I’d be curious to see if WhisperSystems are prepared enough to lawyer up and fight like that. (I suspect they’d probably get NSLed like Lavabit did we won’t know about it until way later...)


According to the Snowden leaks, Apple's been a part of PRISM for quite some time.

Seems to me like the trial was a show for PR, and a win for the FBI because now a ton of people are under the impression that they can commit crimes without a trace if they have an iPhone.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: