Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

In theory, Binary Transparency (https://binary.transparency.dev/) solves that among other things. To pass verification, an update has to prove that it's included in a public log of releases.

But I guess Signal doesn't implement it?



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: