The company behind the Signal clone used by at least one Trump administration official was breached earlier this month. The hacker says they got in thanks to a basic misconfiguration.
Well we don’t know that, the terms say that you need to make the source available to people who got the binary. Either ship them together or ship a written offer for obtaining the source with the binary. You do not have to make the source available to the public (but any of your customers later could).
To verify your claim we would have to get the binary from them, and check if source or an offer for it was included.
Edit: The above is true for GPL2, but it seems Signal is under GPL3, in which distribution of offers of source have been curtailed a bit compared to GPL2, if I’m reading Section 6 here right
Well we don’t know that, the terms say that you need to make the source available to people who got the binary. Either ship them together or ship a written offer for obtaining the source with the binary. You do not have to make the source available to the public (but any of your customers later could).
To verify your claim we would have to get the binary from them, and check if source or an offer for it was included.
Edit: The above is true for GPL2, but it seems Signal is under GPL3, in which distribution of offers of source have been curtailed a bit compared to GPL2, if I’m reading Section 6 here right