Hacker News new | ask | show | jobs
by mfwoods 1928 days ago
But you can verify that the source they publish on Github is the same that was used to built the Google Play version with reproducible builds[1]. Also, Android apps are fairly easy to decompile. They are very likely to get caught if they publish an update with a backdoor.

[1] https://github.com/signalapp/Signal-Android/tree/master/repr...

1 comments

Wow. That's awesome, I could have sworn they opposed to reproducible builds for some reason.