@kravietz Telegram provides reproducible build instructions for both iOS and Android
Signal refuses to provide reproducible build instructions for iOS
Why?
Yes, there are technical hurdles to do reproducible builds on iOS: you need a jailbroken device or one of the unlocked phones from the security research program. But it's possible to do.
@feld@kravietz Levine and a few other former Pando Daily guys have a hardon against Tor too (which does have reproducible builds.) I am really suspicious of the attacks on Tor/Signal because they never have a smoking gun just "look who made it." I can't discount them either but they feel so motivated to me like they're being paid to be attack dogs. I can't prove anything.
@kravietz you should pay more attention to Yasha Levine who has done extensive research on the US Govt's role in subverting internet security back to the origins of it in Vietnam. Go pick up a copy of Surveillance Valley, plenty to learn in there.
@beardalaxy@sun@kravietz Tor is something that needs enough usage to hide the traffic of spies and shit, really. Its in their best interests to have as much noise on that network as possible.
@sun@kravietz@feld signal just freaks me out a little bit because you need to sign up with your phone number. Session is the better choice if you're looking for privacy. They literally can't give out that information because they don't have it, whereas Signal has complied with orders and given numbers before iirc. Could just use a burner phone or something but, you know, still.
Tor is funded by the government but they use it too, it's in their best interest to keep it as safe as it is. They don't need to do anything crazy to catch people with bad opsec (dread pirate Roberts for instance) and most of the time they're just using honeypots anyway (like those "hire a hitman" services), not that the network itself is compromised. As long as you don't have an entire string of government connections then you're good, and if you're really concerned then you can always use a new connection on every site. Someone going to those lengths probably has a lot more shit they need to worry about lol.
@beardalaxy@kravietz@feld if you actually need Tor security you need to run a bridge in your home at all times and attach to that so that your traffic cannot be correlated via connection time. This is how the police caught a guy at Harvard making a bomb threat.
@feld@kravietz@beardalaxy there's a piece about tor on levine's website that covers his entire position on it, it has an unflattering portrait of roger dingledine on it