this post was submitted on 13 Mar 2025
18 points (78.1% liked)

Privacy

2034 readers
385 users here now

Welcome! This is a community for all those who are interested in protecting their privacy.

Rules

PS: Don't be a smartass and try to game the system, we'll know if you're breaking the rules when we see it!

  1. Be civil and no prejudice
  2. Don't promote big-tech software
  3. No reposting of news that was already posted
  4. No crypto, blockchain, NFTs
  5. No Xitter links (if absolutely necessary, use xcancel)

Related communities:

Some of these are only vaguely related, but great communities.

founded 5 months ago
MODERATORS
 

Someone made a compilation of academic reviews and blogposts here: https://community.signalusers.org/t/wiki-overview-of-third-party-security-audits/13243 but none of them seem to be real security audit reports, ex. compare with real security audits to Delta Chat: https://delta.chat/en/help#security-audits

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 22 points 1 month ago (1 children)

You can always look at their history "complying" to government orders to hand over user data.

https://signal.org/bigbrother/

No company is going to break the law for you, so live tests seem about as good as a security audit.

[–] [email protected] 8 points 1 month ago (4 children)

You can always look at their history “complying” to government orders to hand over user data.

IIRC by US law they are not allowed to disclose requests from US gov itself

so live tests seem about as good as a security audit.

I would rather prefer real security audits

[–] [email protected] 4 points 1 month ago

A security audit would be great, but their most recent request was from Santa Clara county, and several previous ones are also from US jurisdictions. You can read about the content of what they were able to provide to the courts.

They're obviously private. And if you're concerned about the app, use the fork Molly.

I guess I don't see what more a security audit would reveal that we couldn't deduce by examining the code or real-life examples.

[–] [email protected] 3 points 1 month ago (1 children)

I would also prefer a server in a jurisdiction that I choose as suitable for my needs. Or, better, a mini-computer on my balcony.

[–] [email protected] 2 points 1 month ago (1 children)

I only talk quietly in loud rooms, can’t trust Signal.