Cykros on Nostr: Signal has for years been an issue in that it is only distributed officially on the ...
Signal has for years been an issue in that it is only distributed officially on the official repositories for Android and iOS. And this opens you pretty wide up to have an update pushed, as these repos are tantamount to a root kit.
Moxie Marlinspike has had this issue brought to his attention for years at this point, and his unwillingness to truly address it speaks volumes.
At the end of the day it all depends who you're trying to ensure privacy from. If it's the NSA, you really should consider using One Time Pad cryptography, which is unbreakable when implemented correctly, but is far from convenient. Anything else should be considered to be taking short cuts -- which are always going to be worth weighing the risk/benefits of.
Moxie Marlinspike has had this issue brought to his attention for years at this point, and his unwillingness to truly address it speaks volumes.
At the end of the day it all depends who you're trying to ensure privacy from. If it's the NSA, you really should consider using One Time Pad cryptography, which is unbreakable when implemented correctly, but is far from convenient. Anything else should be considered to be taking short cuts -- which are always going to be worth weighing the risk/benefits of.