Hacker News new | ask | show | jobs
by Cyph0n 3471 days ago
With such a system, you must end up trusting a certain entity; it's turtles all the way down otherwise. No system is independently secure.

Similar questions include: What if a CA is compromised? What if Apple/MS bundles unwanted certs with the OS? What if Intel/AMD biases the on-die hardware RNG or other hardware crypto primitives? What if Apple/MS bundles a backdoored compiler a la "Reflections on Trusting Trust"? What if MS/Apple backdoor the entire network stack, including the physical and data link layers? etc. etc.

1 comments

Does Signal support reproducible builds, at least? Real question, I don't know.
Partially. They're moving towards it, but it obviously doesn't help that only half of the app is actually open source.