this post was submitted on 13 Mar 2025
50 points (91.7% liked)

Privacy

35465 readers
265 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
 

Someone made a compilation of academic reviews and blogposts here: https://community.signalusers.org/t/wiki-overview-of-third-party-security-audits/13243 but none of them seem to be real security audit reports, ex. compare with real security audits to Delta Chat: https://delta.chat/en/help#security-audits

you are viewing a single comment's thread
view the rest of the comments
[–] Melody@lemmy.one 4 points 10 hours ago (1 children)

Lack of detailed audits...only in this case specifically...does not imply lack of security and/or privacy.

The protocol that Signal uses, which is in fact firmly audited with no major problematic findings, plus the fact the client is OSS is generally enough to lower any concerns.

The server side software in production for Signal.org is not OSS. It will not be. You are required to trust the server to use Signal; because the protocol and the client renders it factually impossible for the server to spy on your messages. The server cannot read messages; or even connect who is messaging who if the correct client settings are used. (Sealed Sender).

Non-OS stats software in general is not automatically lacking in privacy or security, particularly not in this case where the affected software does interact only with software that is verifiably open-source and trustworthy in general due to the protocols and how they are implemented correctly in a verifiable manner.

[–] MonkderVierte@lemmy.ml 0 points 9 hours ago

Non-OS stats software in general is not automatically lacking in privacy or security

Sure is. It's only that in this case you are sure that your messages are sufficiently protected, so you can send them over a untrusted service.