I heard about that you can check via a hash code if the Signal Open Source Code the same code like the App Store Code is this true, have some one more informatons about this ?

riccardo
link
fedilink
7
edit-2
3Y

The Android app allows reproducible builds since 2016:

As of our latest Android release, Signal builds are reproducible. Reproducible builds help to verify that the source code in our GitHub repository is the exact source code used to build the compiled Signal APK being distributed through Google Play.

Anyway:

Remaining Work

Reproducible builds for Java are simple, but the Signal Android codebase includes some native shared libraries that we employ for voice calls (WebRTC, etc). At the time this native code was added, there was no Gradle NDK support yet, so the shared libraries aren’t compiled with the project build.

Getting the Gradle NDK support set up and making its output reproducible will likely be more difficult.

No idea if progress has been made about native shared libraries, but there are probably more info about this in their reproducible builds readme

I don’t think this is available for the iOS app (there is an open issue on GitHub about this)

As of our latest Android release, Signal builds are reproducible.

Not true anymore. however, the Telegram one is. :)

But you know, if the server is proprietary…

And I’ll add that as soon as you use an iPhone or Android, it’s dead anyway.

I mean, the code is on the server, you can’t know if they’re really using the same source code anyway

Vostronix
creator
link
fedilink
13Y

but is E2E so should be fine

Vostronix
creator
link
fedilink
13Y

Telegram is a reproducible build, just on Android or also in iOS

Vostronix
creator
link
fedilink
13Y

ohh nice to see there have something like this. thx for the info :)

Long hashes like SHA-256 or SHA-512 are quite good for binary verification. Reproducible builds as noted by top commenter are also helpful, if possible.

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
  • Don’t promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

  • 0 users online
  • 14 users / day
  • 18 users / week
  • 24 users / month
  • 15 users / 6 months
  • 20 subscribers
  • 619 Posts
  • 1.56K Comments
  • Modlog