Notices where this attachment appears
-
Embed this notice
@iska @DarkSky
> signal needs a phone number
Irrelevant when it can't do anything with it.
> GCM
Do you even know what this is? Every website, including the fedi instance you're on, uses AES-GCM. You don't even know what this means. Please educate yourself: https://en.wikipedia.org/wiki/Block_cipher_mode_of_operation#Galois/counter_(GCM)
XMPP, Matrix, and pretty much everything else, uses AES-GCM by default. The only sane alternative is ChaCha20-Poly1305, not that it matters. Both are safe and well tested.
> while discouraging anything but google-play and app-store builds and being hostile to forks
Without the official app or approved app which has code correctness, any contactt on the other side could be compromised due to the app on your side not sending back necessary data. This is not about freedom, but real security and privacy.
> Can silence even use signal's servers?
Silence is dead. It has been unmaintained for a very long time, other than translations:
https://git.silence.dev/Silence/Silence-Android/-/commits/master
> You still have to trust signal doesn't leak metadata
You don't; proven in court twice, and you can clearly see how all of it works in-app.
> GP/AS builds being safe and private
You can get it directly from Signal's site, and they allow reproducible builds.
Sorry, you lose. Try again, cultist.