Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You also have to trust the source code, or trust a recent audit, then also make sure the build you have kept it's integrity and matches the audit build.


There are degrees of security between "I personally built it from source using a compiler I personally built from source" and "Xi Jinping is CC'ed a plaintext copy of every message". The allegation here is that WeChat is basically the latter. No one makes any remotely similar claim about iMessage or WhatsApp.


If you have never read "Reflections on Trusting Trust" by Ken Thompson, I wholeheartedly recommend it. It's a short read (3 pages), but absolutely worht your time.

https://www.archive.ece.cmu.edu/~ganger/712.fall02/papers/p7...


Why is your link downvoted?


People might've mistaken it for pedantry/condescension? I certainly didn't take it that way (gave it an upvote) -- though I have read that paper, and was thinking of it when I wrote my original comment :)


It was not my intention to be condescending. I legitimately enjoyed that paper (the technical part mostly), and thought it was relevant to what you were saying. I've found a lot of many interesting articles in hackernews comments and wanted to share one back.


You forgot "I personally built it from source using a compiler I personally built from source with a micro-compiler that I handcoded in assembly on a computer that I assembled from transistors myself."


But what if the transistors contain microchips that are phoning home?

Clearly the only solution is to forage your own silicon for artisanal fabrication of your own chips.


All of which you did inside a simulated world built for spying on you. There’s no theoretical ability to verify the whole stack.


How about "Mark Zuckerberg is CC'ed a plaintext copy of every message"


Better Zuckerberg than Xi. Zuckerberg has no power to have a bag put over anyone's head and have them carried away to the river.


Not yet anyway - remember his “listening” campaign and seeming murmurs of entering politics. He’s still young, unlike Winnie the Pooh...


Even if he did enter politics (in America), it’s not at all the same thing.


I wouldn’t trust him not to use all the tools at his disposal to grasp the levers of power. He’s a stone sociopath IHMO.


The question was: do we have any reason to believe it's more secure than weChat? I say yes but those are all valid points.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: