this post was submitted on 27 Jan 2026
834 points (99.6% liked)
Technology
79355 readers
4240 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Signal uses reproducible builds for its Android client, and I think for desktop as well. That means it's possible to verify that a particular Signal package is built from the open source Signal codebase. I don't have to trust Signal because I can check or build it myself.
If I don't have extreme security needs, I don't even have to check. Signal has a high enough profile that I can be confident other people have checked, likely many other people who are more skilled at auditing cryptographic code than I am.
Trusting the server isn't necessary because the encryption is applied by the sender's client and removed by the recipient's client.
Maybe but that doesn't mean you have the same app they do, Google may have different apks for people who could check it and for those who won't.