pull down to refresh

have you check Radar? #1521003 it supposed to be a clone and compatible with signal. did not test yet

I glanced. It's sloppy af and has anti-features. So not unless Signal fucks up more than they do, and even then, cheaper to just patch Signal than to take on a year or more of review debt on generated code.

reply

PS: they also don't defend against supply chain vulns -> GHSA-7xpr-hc2w-34m9

So perhaps you should wait a bit with installing that.

reply
126 sats \ 3 replies \ @ek 27 Aug

I heard it also disconnects you in the official Signal app. If that's the case and there's none, there should be a warning.

Oh, and I don't get the appeal of mixing payments with messages.

reply

Ouch!

I'm not eager to review this one - also because that one above was just a random vuln I checked on the spot because I remembered it from 2 weeks ago or so - I think imma do a pass on this. I also don't understand why you would take the supply chain risk of having breez sdk in your secure messenger. All that ffi, bridges and cargo hell... <what can possibly go wrong>? I already cry every time i have to do signal (kotlin)->ringrtc (rust)->webrtc (c++) review, which is about every other release, meaning 3x per month or so.

This "integrated payments" feature is something I'll probably never understand though. I don't want my money exposed to a thing that literally takes crap in from outside, or my confidential messages exposed to SDKs that interface with public networks. Sandboxing is a thing.

reply
228 sats \ 1 reply \ @ek 27 Aug

I honestly believe you can sell anything to bitcoiners as long as you say there's bitcoin in it (no bitcoin actually needs to be in it). We’re all more normies than not.

reply
reply