2026-08-13 08:32 UTC
@david_chisnall@infosec.exchange @arcanechat@fosstodon.org The whole point to end to end encryption is that neither the network nor the server has to be trusted to protect message content.
The point to Signal being open source is that the insertion of a backdoor to "escrow" keys or scan decrypted plaintext would be instantly caught due to it likely being under a microscope by mutually opposing parties.
It is reasonable to treat AWS and the Big Telcos providing every link between the phones of users as malicious, so Signal is designed to resist such attacks.
Whatsapp by comparison is closed source and controlled by a proven adversary, Meta. Although it supposedly uses the same comms protocol as Signal, it could be doing anything in the background: snarfing keys, scanning and forwarding data, anything. A really stupid backdoor might be detected using Wireshark but a smart one could be tough to find without access to the source code,
Replies (0)
No replies.