Greetings!

A friend of mine wants to be more secure and private in light of recent events in the USA.

They originally told me they were going to use telegram, in which I explained how Telegram is considered compromised, and Signal is far more secure to use.

But they want more detailed explanations then what I provided verbally. Please help me explain things better to them! ✨

I am going to forward this thread to them, so they can see all your responses! And if you can, please cite!

Thank you! ✨

  • Dessalines@lemmy.ml
    link
    fedilink
    arrow-up
    2
    ·
    23 hours ago

    The server is supposedly open source, but they did anger the open source community a few years back, by going a whole year without posting any code updates. Either way that’s not reliable, because signal isn’t self-hostable, so you have no idea what code the server is running. Never rely on someone saying “just trust us.”

    • Valmond@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      3 hours ago

      I have read that it is self hostable (but I haven’t digged into it) but as it’s not a federating service so not better than other alternative out there.

      Also read that the keys are stored locally but also somehow stored in the cloud (??), which makes it all completely worthless if it is true.

      That said, the three letter agencies can probably get in any android/apple phones if they want to, like I’m not forgetting the oh so convenient “bug” heartbleed…