Hacker News new | ask | show | jobs
by ohbtvz 1327 days ago
How terrible of them, packaging open source software for their distribution like so many package managers do.
1 comments

I'm the last person to defend lawyers, DMCA takedowns, etc. But Signal has very strict build processes in place to ensure (to the best of their ability, anyway) that the official binaries are devoid of side-channel attack vulnerabilities.

Putting my tinfoil hat on, all it takes is one unofficial Snap maintainer to be approached by one Glow-In-The-Dark with an offer they can't refuse to infect a hundred thousand users with key material compromise.

I hate to say it, but Signal is doing the right thing, here.