▲ | palata 6 days ago | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
I was not talking about a security flaw. I was saying that maybe, Signal did not want to push their users to trust the Apple backup by default. Signal is a nonprofit foundation, it's not like they are trying to squeeze their users with their own secure backup. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
▲ | Y-bar 6 days ago | parent | next [-] | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
We are unfortunately rehashing the same arguments from Github, nothing prevents Signal from distrusting Apple by default. But there is also nothing (except for some secret reason they refuse to elaborate) that prevents them from allowing users to actively chose to trust Apple. Except for their own internal reasons, that is. It's the user's data after all. The user should be able to control and access it. Sensible defaults makes sense, but the outright refusal to explain why they prevent it is very odd. I have a decent "IT hygiene", I keep my operating system updated with patches, I don't download pirated/cracked software, I have hardware-enabled encryption on my storage devices, I have a good password for my local account, I encrypt my local iPhone backups. Why should I not be allowed to include my Signal chats in those local backups? Signal has never answered that question, which is very strange. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
▲ | AnonC 5 days ago | parent | prev [-] | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
> I was saying that maybe, Signal did not want to push their users to trust the Apple backup by default. The gap in understanding here is that Signal already trusts iOS by providing an app. It trusts it even more by providing notifications (with sender and content) that go through Apple’s systems. It integrates with CallKit to work with the Phone app. Putting iCloud alone in a separate bucket doesn’t make sense. They could’ve done this same backup with a 64 character recovery key and stored the data in iCloud. Signal made an intentional choice not to allow backups on iOS. One can only hope that the point about supporting other backup endpoints/storage gets implemented sooner rather than having to wait several more years. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|