Hacker News new | ask | show | jobs
by lucb1e 1569 days ago
> Signal publishes the fingerprint on their website: https://signal.org/android/apk/

Ah, fair point, there indeed my logic does not apply. On GitHub releases with apk downloads, I've never seen a fingerprint and including it on the GH platform itself would not help either, but indeed nothing prevents the maker from using some other place to publish key material.