|
|
|
|
|
by cottsak
444 days ago
|
|
I find "bypassing end-to-end encryption" to be misleading... as if somehow the e2e encryption in Signal is somehow broken or flawed. This "social engineering" hack? is simply allowing a 3rd party to gain access to another persons account and "snoop" on their secured messages/calls. Pls correct me if I'm reading this wrong. |
|
However, I think there is a real possibility that the Signal code (of which the public appstore versions are NOT fully open-source) could be modified to save/transfer messages after they have been decrypted, basically circumventing the whole point of e2ee... which is why having control over the client code is essential.
I suggest either building Signal yourself, using only verified reproducible builds without any binary blobs, or switching to the Molly-FOSS fork.