Hacker News new | ask | show | jobs
by DonCopal 2337 days ago
But how can you be sure there's no additional code being run on their server?
1 comments

It doesn't matter as the messages are end to end encrypted and the way it is done is continously verified by multiple leading/up-and-coming cryptographers as far as I understand.

This is the huge advantage that Signal has over mail, the default mode in Telegram and pretty much anything there is: it does matter if NSA, FSB, MI5, Mossad, Google and Facebook all have root on a server that all the traffic passes through. To the best our knowledge - long as they don't compromise one of the endpoints - the only thing they'll get is metadata and the only thing they can do is disrupting the service.