you are viewing a single comment's thread
view the rest of the comments
[–] 19 points 5 months ago (5 children)

Maybe the security expert could read the readmes in the repos first. From the iOS app repo:

The initial development release has reduced security, privacy, availability, and reliability standards relative to future releases. This could make the software slower, less reliable, or more vulnerable to attacks than mature software.

And further:

If you're planning to use this application in production, we recommend reviewing the following steps: […] The Pin storage configuration matches your security requirements, or provide your own by following this guide Pin Storage Configuration […]

So the text hints not at design flaws but at facts that are already stated in the readme. Plus, the major source for the article is Pavel Durov, who’s messenger is of course a standard in security and privacy.

So there seems to be no news but a lot of speculation by Durov instead.

  • source
  • hideshow 5 child comments
  • [+] -8 points 5 months ago (2 children)

    I really hope the manage to do this properly. I'm all for verification on the internet, but only if it is fast, secure and reasonably private. You can do it, but noboy has so far

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 5 months ago (1 child)

    You can do it, but noboy has so far

    What's your assessment of the German eID and AusweisApp2 that has been in use for many years?

  • source
  • parent
  • hideshow 1 child comment
  • [–] 2 points 5 months ago

    I can say that it works fine for me, although I'm not up to speed regarding its security. I like that it explicitly tells me what kind of data is requested and by whom. The problem here is mainly low adoption. If they rolled the exact thing out EU wide, it would probably gain more traction. It's a joke they have no official Linux support despite having an Android app tho

  • source
  • parent