Live data from Hacker News

Grand jury subpoena for Signal user data

whispersystems.org

41–50 of 258 posts

Re: Grand jury subpoena for Signal user data

#41
post #5

It'd be better, of course, if we didn't rely on Signal not storing all that metadata and instead used a protocol which made it impossible for anyone to be in a position to choose whether or not to store it. Unfortunately, the protocols that enable truly traffic–analysis-resistant messaging (I believe the Pynchon Gate[1] is currently the best-of-breed) tend to have increased latency and consume greatly-increased bandw…

Yeah, but I'm kind of tired of having to fight my own government every step of the way. I'd prefer a political solution at this point.

Why not both?

Re: Grand jury subpoena for Signal user data

#43

I'm not too surprised to see an attempted overreach by federal investigators. Too bad there's no measure of meaningful accountability here. Outside the usual "let's ask for more than we're legally entitled" shtick, there's nothing particularly alarming about this subpoena; it was narrowly focused on two phone numbers, for which only one was a Signal user. It's good on OWS to fight so hard for transparency.

[deleted]

Re: Grand jury subpoena for Signal user data

#44
post #20

Earlier quoted context omitted.

That doesn't prove they don't have it though. I'm skeptical of the suggestion as well, but people can lie.

Since their client apps are OSS you can check yourself: https://github.com/WhisperSystems/Signal-Android

But isn't this server-side meta-data, not client-side meta-data? The service still routes through their system.

Re: Grand jury subpoena for Signal user data

#45
post #36

Earlier quoted context omitted.

Yeah, but I'm kind of tired of having to fight my own government every step of the way. I'd prefer a political solution at this point.

Political solutions change as politics change: I think it's better to be mathematically secure than politically secure, since the one is forever and the other only sure until the next election.

They can just make it illegal to own a mathematically secure piece of software without a license.

Re: Grand jury subpoena for Signal user data

#46
post #4
post #3

FYI, Signal has access to all metadata about messages and calls (but not the content of course). They claim not to store it and I believe them for now but someone else could be storing it. They don't have access to group message membership directly. A group appears as a bunch of one to one messages between the participants, so they might still be able to infer it.

If they were storing that metadata, they would be lying in the response to their subpoena.

I think you misread woah's comment. Signal has access to the metadata but chooses not to store it in order to be able to remain unresponsive to queries like this.

Re: Grand jury subpoena for Signal user data

#47
post #8

Earlier quoted context omitted.

What metadata? All they were able to produce was whether or not a phone number was associated with Signal at all , and the last time that phone number's account pinged the Signal service for any reason . They produced virtually no metadata to the investigation.

Exactly, did he read the article?

https://news.ycombinator.com/newsguidelines.html

"Please don't insinuate that someone hasn't read an article. "Did you even read the article? It mentions that" can be shortened to "The article mentions that."

Re: Grand jury subpoena for Signal user data

#48
post #5

It'd be better, of course, if we didn't rely on Signal not storing all that metadata and instead used a protocol which made it impossible for anyone to be in a position to choose whether or not to store it. Unfortunately, the protocols that enable truly traffic–analysis-resistant messaging (I believe the Pynchon Gate[1] is currently the best-of-breed) tend to have increased latency and consume greatly-increased bandw…

Yeah, but I'm kind of tired of having to fight my own government every step of the way. I'd prefer a political solution at this point.

To me, the big question is what a trustworthy political solution would look like.

I see this desire raised a lot, in contexts from HN to Valley-mocking pieces on how encryption is no substitute for advocacy. I completely understand the instinct, but every incarnation of it seems to struggle with the same question. Namely: how do you know when you've won?

Restrictions against collecting data on US citizens didn't produce the expected results. Testimony to Congress didn't accurately depict what's collected, even in secret. In the early days, the existence of these agencies was classified to help go around restrictions on existing agencies. Years ago, back in the Puzzle Palace days, the DoJ cited systematic criminality but concluded that they were unable to prosecute it.

So... what does winning look like? What regulation, what testimony, what promise could possibly convince people that a solution had been reached, even for the moment?

Re: Grand jury subpoena for Signal user data

#49
post #5

It'd be better, of course, if we didn't rely on Signal not storing all that metadata and instead used a protocol which made it impossible for anyone to be in a position to choose whether or not to store it. Unfortunately, the protocols that enable truly traffic–analysis-resistant messaging (I believe the Pynchon Gate[1] is currently the best-of-breed) tend to have increased latency and consume greatly-increased bandw…

What about Vuvuzela? Haven't thoroughly examined it, but it focuses on metadata-privary and -relative- scalability. web: https://vuvuzela.io/ repo: https://github.com/davidlazar/vuvuzela paper: https://davidlazar.org/papers/vuvuzela.pdf slides: https://davidlazar.org/slides/vuvuzela-sosp2015.pdf

There's also an updated, more distributed and thus (maybe) more scalable project by some of the same authors:

https://eprint.iacr.org/2016/943

Re: Grand jury subpoena for Signal user data

#50
post #36

Earlier quoted context omitted.

Political solutions change as politics change: I think it's better to be mathematically secure than politically secure, since the one is forever and the other only sure until the next election.

They can just make it illegal to own a mathematically secure piece of software without a license.

[deleted]
Post reply on HN