Hacker News new | past | comments | ask | show | jobs | submit login

Okay, but that's not what any of the parties in this current case are doing: the Snap in question is a third-party build, not a source distribution.

My understanding (as an outsider) is that Signal doesn't object to you building yourself a copy of Signal Desktop for source, but they do object to anybody building it for others, especially when they brand it as "Signal." That doesn't seem especially unreasonable to me: E2EE is a domain where trust is established exactingly; a proliferation of unreviewed third-party builds compromises environmental trust.




I already trust Debian's repositories with my system; so getting Signal from Debian's repositories would not make my system or Signal more vulnerable. By adding Signal's deb repositories, I need to also trust Signal not to mess with the rest of my system.


The Snap's build instructions do nothing but download the .deb and repackage it into a Snap.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: