The Signal Server repository hasn’t been updated since April 2020. There are a bunch of links about this here but I found this thread the most interesting.

To me, this is unforgivable behaviour. Signal always positioned themselves as “open source”, and the Server itself is under the best license for server software (AGPLv3 – which raises questions about the legality of this situation).

Signal’s whole approach to open source has constantly been underwhelming to say the least. Their budget-Apple attitude (secrecy, i.e. “we can never engage the community directly”, “we will never merge/accept PRs”, etc) has lead to its logical conclusion here, I guess. I have been somewhat of a “Signal apologist” thus far (I almost always defend them & I think a lot of criticism they get it very unfair) but yeah I’m over Signal now.

  • @federico3@lemmy.ml
    link
    fedilink
    13 years ago

    Leak less metadata

    citation needed. On the contrary, any network observer can perform a timing attack by correlating messages being exchanged to/from clients and servers. Having centralized servers only makes it easier.

    Briar, on the other hand, is P2P and uses Tor as transport network making such attack way more difficult.

    • Dreeg Ocedam
      link
      fedilink
      03 years ago

      I edited the comment with citation.

      Briar suffers from the problems I mentioned about P2P requiring more battery and not being able to use push notifications. It also has the works UX of the lot, since you can’t even begin communicating with someone without being in having a way to get them a cryptographic identifier/QR code. No way anyone but the most tech savvy will ever use it. Also, it’s still not available on IOs.

      • @federico3@lemmy.ml
        link
        fedilink
        13 years ago

        To protect users metadata including the type of application, protocol, and timing push notifications cannot be used. Equally, direct connections to centralized servers are not suitable. That’s a reason for Briar to use Tor.

        The thread is about centralized vs decentralized. Availability on OSes, polished UIs and so on are besides the point.

        • Dreeg Ocedam
          link
          fedilink
          -13 years ago

          The thread is about centralized vs decentralized. Availability on OSes, polished UIs and so on are besides the point.

          Yes, your are obviously right. Who cares about the end user? /s