this post was submitted on 28 Aug 2024
80 points (87.7% liked)

Technology

58063 readers
3097 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
 

Rufo’s article went viral, and was shared by Twitter founder Jack Dorsey, and Ethereum inventor Vitalik Buterin, and Elon Musk commented, “Yup, concerning.” Musk then claimed without evidence that “there are known vulnerabilities with Signal that are not being addressed. Seems odd…” Musk’s tweet was refuted by X’s own Community Notes.

Most importantly, Telegram’s Durov used Rufo’s blog post and the conservative energy behind it to promote Telegram as an alternative and made sweeping claims about the security of Signal without having anything to back it up: “A story shared by Jack Dorsey, the founder of Twitter, uncovered that the current leaders of Signal, an allegedly ‘secure’ messaging app, are activists used by the US state department for regime change abroad,” Durov wrote on his own Telegram channel. “An alarming number of important people I’ve spoken to remarked that their ‘private’ Signal messages had been exploited against them in US courts or media ... for the past ten years, Telegram Secret Chats have remained the only popular method of communication that is verifiably private.”

One of the greatest things in the world, imo, is how these idiots promoted an insecure platform for shitheads to think they're conspiring in private.

top 8 comments
sorted by: hot top controversial new old
[–] [email protected] 11 points 2 weeks ago

Ya know, Signal has been audited multiple times. It's OSS. IT sec elite has looked at it and says it's sound. If anything is plausible, it would be your device spying on you rather than Signal.

What's weird tho is how people think this has anything do with messaging or data privacy. This is about Telegram being used as a public platform. They can't force Durov to decrypt anything, nor do they need to, because they already know your groups...

[–] [email protected] 14 points 2 weeks ago

Idiots who before didn't bother to learn how to tell insecure platforms at that. In other words - those who only started caring about security when being sold it.

[–] [email protected] -1 points 2 weeks ago* (last edited 2 weeks ago)

Any billionaire shouldn't be. Any billionaire who believes in and lives an "ascetic" lifestyle should live an ascetic lifestyle in a prison cell. Such a heightened contradiction, hoarding wealth and asceticism.

[–] [email protected] 39 points 2 weeks ago (1 children)

“A story shared by Jack Dorsey, the founder of Twitter, uncovered that the current leaders of Signal, an allegedly ‘secure’ messaging app, are activists used by the US state department for regime change abroad,” Durov wrote on his own Telegram channel.

In fact, the folks running Signal — notably Moxie Marlinspike and Meredith Whittaker — have a long history of effective security & privacy activism. Whittaker was one of the organizers of the Google Walkouts, one of the more effective pieces of tech worker activism in recent history. And Moxie has bumped heads with the US intelligence community more than once, and famously with the Saudis too.

[–] [email protected] 8 points 2 weeks ago (1 children)

Signal's hostility to 3rd party clients, and their refusal to publish on F-Droid is a massive red flag. I will not be using until they start following common sense.

[–] [email protected] 12 points 2 weeks ago (1 children)

Why will they not use F-Droid?

[–] [email protected] 17 points 2 weeks ago (1 children)

They won't directly support it because in their view the Google Play process is a more secure way of verifying they supplied the binaries than is possible of f-droid. If reproducible builds were possible maybe there could be some mechanism to verify a given binary is built from a given commit of the source tree.

[–] [email protected] 13 points 2 weeks ago

Doesn't Google play store also modify and build the binary themselves to "generate and deliver APKs that are optimized for each device configuration, providing users with more efficient apps"?

https://support.google.com/googleplay/android-developer/answer/9859152#apk