Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You replied to a fictitious argument. What I said is that security is not that simple, it matters on your threat model, and things like resilience and platform diversity matter too. Crypto is not the weak link for Signal (nor is it likely to be for comparable products).

What claudius said was that in essence was that a trusted application should not depend on giving remote root to Google, likely referring to not be able to compile and distribute the software in a useful way. That is worth a more meaningful answer. Distribution and the run time environment are central to any realistic threat model and reducing that to open source zealotry kind of misses the point.



Crypto has already been the weak link in other "secure" messaging applications.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: