• ramenu@lemmy.ml
    link
    fedilink
    English
    arrow-up
    0
    arrow-down
    2
    ·
    22 days ago

    What? How is this a red flag? Having third party clients is not good for security.

      • ramenu@lemmy.ml
        link
        fedilink
        English
        arrow-up
        0
        arrow-down
        1
        ·
        22 days ago

        When you use a client, you are relying on the client’s crypto implementation to be correct. This is only one part of it and there’s a lot more to it when it comes to hardening the program. Signal focuses on their desktop and mobile clients and they hire actual security professionals and cryptographers (unlike the charlatans in this thread) to implement it correctly.

        Having third party clients would not definitively mean the client is bad, but it most likely would break the security model. Just take a look at Matrix’s clients.