Reproducible builds are nice, and I would love to have them for Signal. But I think I disagree with most of what you've written.
Enabling "unknown sources" does not make my device less secure. The setting is also disingenuously named: It is in fact "known sources" I am installing (not "sideloading") software from. It is just not a source Google wants to know of.
I also do not need to reproduce every new release from source. It is a signed APK I'm getting from signal.org.
If the antagonists in my threat model are so capable they could serve a tailored, signed APK from signal.org for the IP I'm using, I should absolutely not use a messenger whose identifier is my phone number, aka my real world identity AND permanent location marker. That feels absurd. A threat actor that capable could just locate me, pick me up and shake me until I unlock the device.
You are saying Molly exists and works fine, so I'm not really sure the whole problematization of Signal holds up. Does the existence of Molly not disprove your criticism that users would have to use the mainline Signal app from the Play Store?
I think it might be a good sign that criticism of Signal tends to presuppose absurdly capable threat actors. It suggests there is little low-hanging fruit left to criticize.
> Enabling "unknown sources" does not make my device less secure. The setting is also disingenuously named: It is in fact "known sources" I am installing (not "sideloading") software from. It is just not a source Google wants to know of.
By disabling signature verification you open yourself up to man-in-the-middle attacks and supply chain attacks. How do you know the signal CDN account was not compromised to serve certain IP addresses different signal binaries with backdoors? Independent reproducible build signatures, like f-droid supports, are the only way out of this, which f-droid offered to do and was refused. Accountability was refused.
> If the antagonists in my threat model are so capable they could serve a tailored, signed APK from signal.org for the IP I'm using, I should absolutely not use a messenger whose identifier is my phone number, aka my real world identity AND permanent location marker. That feels absurd. A threat actor that capable could just locate me, pick me up and shake me until I unlock the device.
Do you think the Signal team signs all their Android binaries in a full source bootstrapped secure enclave that requires a quorum of signal team members to sign each release following their own deterministic builds and code review to ensure only a -single- variant of every version of Signal exists with multi-party verified code with multi-party verified signatures?
It would be weird to keep it secret if they did all this work for public safety. I do this sort of thing for most projects and am pretty loud about it so people understand they do not need to trust me.
Instead, it is likely how everyone else does it. A release engineer builds and signs it with a key they fully control, that could be coerced or bribed or given a secret court order.
That is a massive massive single point of failure for a messenger whose goal is supposedly privacy without having to trust the Signal foundation.
Their negligence in supply chain security gives them, Google, and Apple an incredible amount of power to covertly backdoor any conversation at any time, for seemingly no reason.
> You are saying Molly exists and works fine, so I'm not really sure the whole problematization of Signal holds up. Does the existence of Molly not disprove your criticism that you have to use the mainline Signal app?
Molly only helps if both sides of the conversation are using it. At that point the network effects of Signal, and the privacy loss of being forced to identify yourself, no longer makes sense. Both parties could use an open network alternative instead.
Also I personally do not use Android or iOS so I am not welcome on the Signal network at all afaict.