Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The article is clear: download from the Signal site is not secure.


Based upon what? The download is served via HTTPS, and offers a checksum also secured via HTTPS. Are we entertaining security models in which PKC is considered "not secure"?

Or are we just going by the author's ignorant or disingenuous (depending on how you interpret his words) statements?


Checksummed but not signed.


SSL provides integrity guarantees.


Only a bit of transport level integrity. But it doesn't make your average hosting provider into a high assurance one or its servers, OSes, software stacks, etc. Quite known problem since the cryptocurrency era.


Which is maybe why Moxie is encouraging people to rely on Google Play Store.

If you are so concerned about state-level actors that play store is untenable to you, signal and android on commodity hardware are probably not the solutions you want anyways.


And f-droid somehow is immune to this?




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: