TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Ask HN: Why doesn't Moxie sign Signal's releases?

24 pointsby rahrahrahover 8 years ago
It's good practice and obviously the guy is smart and knows this...

4 comments

comboyover 8 years ago
If it's distributed using Google play store aren't apks signed by the developer anyway?
评论 #13270868 未加载
adricnetover 8 years ago
On Android or iOS or did you mean sign a source release ...?<p>My guess is because of potential friction with reproducible building (for Android) and this for iOS: <a href="https:&#x2F;&#x2F;github.com&#x2F;WhisperSystems&#x2F;Signal-iOS&#x2F;issues&#x2F;1063" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;WhisperSystems&#x2F;Signal-iOS&#x2F;issues&#x2F;1063</a><p>hth, adric
评论 #13270821 未加载
hktover 8 years ago
I don&#x27;t know, but am I right in saying that he is generally in favour of ephemerality over verifiability? It&#x27;d seem odd to do this with definitely attributable works like software releases, but it is what would make most sense to me.
评论 #13271032 未加载
cjbprimeover 8 years ago
Crypto experts don&#x27;t follow &quot;good practice&quot; for the sake of it; they do things that would meaningfully improve security.
评论 #13271018 未加载