this post was submitted on 25 Jun 2023
2 points (75.0% liked)
TechNews
4392 readers
1 users here now
Aggregated tech news.
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Therefore, the implementation distributor cannot be secured against?
Isn't the only defense for this an open source implementation?
If so, isn't Signal doing everything it can?
I get the attack on Lavabit and Protonmail because the implementation is downloaded transparently and often, however Signal's distribution model can be explicit by disabling auto updates, and you can produce the same binary locally.
In summary I think Signal is much better than Lavabit/Protonmail and putting them in the same bucket is disingenuous.