logoalt Hacker News

Krasnol06/16/20252 repliesview on HN

Sure you should be suspicious. You should always be suspicious. Especially if it's free. And you can do something to calm your suspicions. Like checking out Signlas Open Source code.


Replies

gruez06/16/2025

>Like checking out Signlas Open Source code.

What's preventing them from serving a backdoored version? xz was open source as well, that didn't stop the backdoor. There might be reproducible builds on android, but you can't even inspect the executable on iOS without jailbreaking.

show 2 replies
eviks06/17/2025

How would that calm suspicion if you're not arr/ign-orant and understand that continuous security audit is practically impossible at an individual level?