|
|
|
|
|
by rvz
1796 days ago
|
|
> Because I judge a project backed by a company worth hundreds of billions of dollars and with hundreds of developers differently than I judge a company with a few tens of millions and only a dozen developers. Any project that can at least afford a string of external audits and proudly advertises on multiple claims of high quality security and privacy should be held to very high standards, especially if they are serious projects in security and privacy and are not toy or pet projects. Hence this, I would expect all Signal engineers to be the best in their field and qualified in both of these standards to justify the compensation price and uphold these claims for Signal. The same goes for any serious secure messaging platform prioritising security and privacy. The harsh reality is that serious projects and competitors with bold claims of security and privacy all get treated the same. No exceptions or passes. Otherwise it can't be considered a serious project or even recommended to users if they don't prioritise and fix critical issues urgently. > I'm not sure why any sane person would judge these with the same metric. So you're telling me that Telegram or Element are able to prioritise urgent and critical security issues much better than Signal could? Signal is a serious messaging app going with its bold claims of high quality security and privacy isn't it? |
|
No, I'd say it is about the same actually. Telegram has a lot of hacks but HN doesn't throw a fit. Lot more serious ones too. Signal never had an issue with leaking someone's physical location to any user (read: "not a rare set of circumstances needed to reproduce"). Besides, Telegram still isn't e2e by default, doesn't have e2e groups, and has no security audits. I'm not sure why this is in the same category as Signal. As for Matrix, well it only recently enabled e2e. But the project is very small. Just because you don't know of a bug doesn't mean one doesn't exist. There's an old saying: "There's two types of software. Those with bugs and those that nobody uses." (read: "all software has bugs")