Preferences

rjdj377dhabsn parent
The decision to update or not shouldn't be taken away from users.

Frequent updates have the downside of more frequent breakage and of course extra bandwidth usage. Let users make the trade off between those downsides and the risk of zero days.


farixco
The problem is that you're not only putting yourself at risk when you don't update.

You're putting everyone who you've talked to at risk. I don't know about you, but I prefer not having to worry about whether I'm communicating with someone whose installation can easily be pwned by any halfway incompetent attacker.

krater23
It's the same when I install a update that I not personally security reviewed. Sorry, thats not a argument.
godelski

  > a update that I not personally security reviewed
Great, can you give me a summary of the updates for the Linux Kernel, Android Kernel, iOS kernel, libssl, and all the drivers that updated this week on my arch machine?

  > Sorry, thats not a argument.
Neither is pretending you're reviewing hundreds of thousands of lines of code a week.

This is Hacker News man, some of us actually understand how computers work.

godelski

  > update or not shouldn't be taken away from users.
So turn off auto-update? You can do this everywhere except iOS.

  > Let users make the trade off between those downsides and the risk of zero days.
Those trade-offs are that if your version is too old (protocol has been updated several times and you are out of the lifetime) then you can no longer communicate with those who have updated as you will make their communications insecure.

If you don't want to update, that's fine. But your preference for not updating doesn't get to override my preference for secure communication. It is literally the whole point of Signal... if you don't want security and privacy then don't use Signal, that's your choice and no one is forcing you to use the app.

birksherty
Then signal must be very insecure, poorly coded app in first place, that needs to updated every or every other day. They also don't give any explanation of what that updates are.
DANmode
I’d love to red team your workplace.
LtWorf
Is this the 2025 equivalent of "give me your IP address"? LOL.
DANmode
Age/SecuritySkills/Location

This item has no comments currently.