Signal has no known/published real security audit?
-
As I seen in other comment I think that the protocol is audited not really the app and servers
In comparison SimpleX is audited pretty regularlycould you provide some source/link to the SimpleX security audits? I would like to look into it, thanks in advance!
-
does Briar has security audits you could point to? thanks in advance
-
does that one has security audits? thanks in advance
Both signal and molly are considered safe, a lot of apps use the same protocol as signal, most risk come from messages leaks before the encryprion happens.
Unfortunately, I'm not aware if they did external audits, but both codes are available in github.
-
could you provide some source/link to the SimpleX security audits? I would like to look into it, thanks in advance!
This seems to be the latest one. https://simplex.chat/blog/20241014-simplex-network-v6-1-security-review-better-calls-user-experience.html
-
Someone made a compilation of academic reviews and blogposts here: https://community.signalusers.org/t/wiki-overview-of-third-party-security-audits/13243
but none of them seem to be real security audit reports, ex. compare with real security audits to Delta Chat: https://delta.chat/en/help#security-auditsNot a formal audit, but a more recent review of the protocol: https://soatok.blog/2025/02/18/reviewing-the-cryptography-used-by-signal/
-
Not a formal audit, but a more recent review of the protocol: https://soatok.blog/2025/02/18/reviewing-the-cryptography-used-by-signal/
thanks, I think I know that one, but yeah as you said it is not a real security audit and the person itself said so
-
Both signal and molly are considered safe, a lot of apps use the same protocol as signal, most risk come from messages leaks before the encryprion happens.
Unfortunately, I'm not aware if they did external audits, but both codes are available in github.
At a user level, the biggest security compromise with signal is enabling notifications
-
At a user level, the biggest security compromise with signal is enabling notifications
That's a big one, you can disable it, but if the other person has it enabled it can leak it after decryption also.
-
This seems to be the latest one. https://simplex.chat/blog/20241014-simplex-network-v6-1-security-review-better-calls-user-experience.html
Right thank you
-
That's a big one, you can disable it, but if the other person has it enabled it can leak it after decryption also.
Exactly the issue, same as always. Signal got rid of sms because it was insecure but enable reply in notifications by default.
-