logoalt Hacker News

akoboldfryingtoday at 4:24 AM1 replyview on HN

Perhaps it shouldn't necessitate it, but I can't think of a good reason why not.

If it were expensive to release it, that would be a reason. But it costs roughly zero dollars to create a public repo on GitHub and a cron job to push to it once a day.

Making the system public potentially increases the likelihood of a hack, which would be bad for Signal users. But relying on this argument to keep the source secret is, I think, a confession that your security is below par. Or to put it the other way round: A secure software system remains secure even if its source code is public, so making your source public is a strong signal that you are confident in your security measures. Security isn't something I expect all non-profits to focus on, but I think it would be telling for Signal to hide behind this reason.

What other reasons are there?


Replies

Joltertoday at 6:12 AM

How about they: 1. Don’t want hack competitors launching products using their code 2. Don’t want the resulting fracture in the community

If I were Signal I wouldn’t want either of those.