logoalt Hacker News

1vuio0pswjnm7today at 3:53 AM1 replyview on HN

If the Signal Messaging LLC is compromised, then "updates", e.g., spyware, can be remotely installed on every Signal user's computer, assuming every Signal user allows "automatic updates". I don't think Signal has a setting to turn off updates

Not only does one have to worry about other Signal users being compromised, one also has to worry about a third party being compromised: the Signal Messaaging LLC


Replies

heavyset_gotoday at 4:21 AM

Signal Messaging LLC is US-based and needs to follow CALEA[1] by law.

[1] https://en.wikipedia.org/wiki/Communications_Assistance_for_...