• HubertManne@piefed.social
      link
      fedilink
      English
      arrow-up
      8
      ·
      3 months ago

      I don’t think anything can be proven unless you have admin rights to the server at all times. signals are encrypted every time they are sent encrypted. can it be turned off with a flag? does it run in dev without it for troubleshooting and if so is it impossible to enable in prod.

      • icmpecho@lemmy.ml
        link
        fedilink
        English
        arrow-up
        11
        ·
        edit-2
        3 months ago

        okay, so self host it if that is part of your concern/threat model. the Signal server code is open to the public, you can see and download it here.

        • HubertManne@piefed.social
          link
          fedilink
          English
          arrow-up
          6
          ·
          3 months ago

          exactly. if they had self hosted then it would be closer to equivalent to hilaries email but if it was using signal as written but then there is the foia issue which was still possible with hilarys email server, but not under a self hosted signal if not altered.