Hacker News new | ask | show | jobs
by tptacek 1258 days ago
The Threema server isn't open source, is it?
2 comments

You can’t verify the binaries it’s actually running and the protocol shouldn’t rely on a trustworthy server anyway.

IMO the biggest problem with any of these E2EE apps is using them with iOS users. Apple makes it impossible to extract and inspect the packages without jailbreaking, so most projects don’t bother with reproducible iOS builds.

As the paper demonstrates, you did in fact need to trust the Threema server in some respects.
Yeah :(

but that’s why I said “shouldn’t” instead of “doesn’t”.

I don't think it is, which is disappointing. But even with Signal's open sourced server I think we still need to trust that they are running said server. Unless you know a way to verify it.
That was true of Threema, too!