Live data from Hacker News

Grand jury subpoena for Signal user data

whispersystems.org

231–240 of 258 posts

Re: Grand jury subpoena for Signal user data

#231
post #11

Earlier quoted context omitted.

Only because they don't store it. They are able to choose to store it at any point; we can only rely on their honesty (and lack of compulsion). It's better to have a protocol in which there isn't any significant metadata to choose to store. I don't distrust them today, but I have no way of knowing what their future behaviour will be. I'd prefer not to have to trust.

The client is open source[1], we can at least define a limit to what information can be stored that is not end-to-end encrypted. https://github.com/WhisperSystems/Signal-Android

How many people build from source? Moxie worked to stop distribution of binaries outside the Play Store, which is not unreasonable in itself but leaves a nice central point to target individuals.

Re: Grand jury subpoena for Signal user data

#232
post #170

Earlier quoted context omitted.

Or be forced a la Lavabit to install a pen register which would capture the metadata from that point forward.

What is the solution here? The solution that minimizes damage involves everyone building from source and connecting in a peer to peer fashion that makes it pretty difficult to push a malicious update if you're looking for targeted surveillance. However, even this requires an understanding government that isn't willing to poison the well in order to get to the target. A government that justifies dragnet (and whose age…

The obvious solutions is a federated protocol. There's no reason for Whisper or Google to be involved in routing messages except to own the system's concept of identity.

Trust in binaries is a harder problem, but reproducible builds is probably an important part of it. If several separate entities vouches for the binary, you have reason to believe what you run corresponds to be published source code.

Re: Grand jury subpoena for Signal user data

#235
post #5

It'd be better, of course, if we didn't rely on Signal not storing all that metadata and instead used a protocol which made it impossible for anyone to be in a position to choose whether or not to store it. Unfortunately, the protocols that enable truly traffic–analysis-resistant messaging (I believe the Pynchon Gate[1] is currently the best-of-breed) tend to have increased latency and consume greatly-increased bandw…

Can someone explain how people are imagining protocols that do not to create / store metadata? This seems like something fundamentally impossible on a packet-switched network. After all, the data has a source and a destination, and goes through the infrastructure that's tappable (and in big part already tapped) by a state-level actor. About the only thing that comes to my mind would be a digital equivalent to broadca…

In addition to all the systems and protocols mentioned by sibling posters, I'll add ricochet: https://ricochet.im/

It deals with the metadata leaks by using Tor. Every user runs a Tor hidden service, and the users identity is the address of that service. So no single point in the chain can tell who is talking to whom, without having to resort to a broadcast protocol like you describe.

Re: Grand jury subpoena for Signal user data

#236

Earlier quoted context omitted.

Blockchains can do this. But they create relatively absurd systems of who can/can't send messages based on how much they've mined. Block chains are HORRIBLE for encrypted messaging. Since your message is PERMANENTLY part of the chain. So if a encryption is broken, or your password gets leaked. ANYONE can read your messages. In most cases a DHT is far simpler. But naturally some nodes can be evil and log metadata. Thi…

Bitcoin: the slowest, most expensive key/value store in history.

Also if you look at it in terms of the CAP Theorem:

Consistency (every read receives the most recent write or an error): Not True for block chains. All reads are dirty. The further back in time you go the higher the probability the read isn't dirty.

Availability (every request receives a response, without guarantee that it contains the most recent version of the information): 100% true.

Partition tolerance (the system continues to operate despite arbitrary partitioning due to network failures): Yes the system will continue to function. But you can suffer data loss when the partition is healed.

Re: Grand jury subpoena for Signal user data

#237
At the risk of sounding clueless, how is it possible that Signal can’t say which account belongs to which phone number when the only concept of a username on Signal is that of a verified phone number? When I initiate a conversation, am I not at that moment using a lookup which now people are saying does not exist!?

Re: Grand jury subpoena for Signal user data

#238
post #196

Earlier quoted context omitted.

I agree, but I'm talking about a scale even shorter than that. Roe v Wade was a clear and unambiguous advance for abortion rights, and the battle lines are now arrayed somewhere different than they were before Roe. The fight isn't over, but it's fairly clear who holds what. I'm talking about even knowing when you've made progress. If a federal directive came through tomorrow expansively forbidding the NSA from collec…

There have been countless times where courts have told three-letter agencies to stop doing things and they have stoppped . The judiciary has the power to protect us, much more than we give credit for. There's still rule of law, and the executive mostly listens to what the judiciary tells it to do. For all its flaws, some of our institutions work pretty well compared to most places. I cannot think of another country w…

I'd actually be interested to see examples. Most of the ones I know are of courts and Congress ordering three letter agencies to stop doing things, and being lied to and ignored.

The infamous one: in its early days, the NSA was ordered to stop surveillance of US citizens. It went before the Church Committee and testified that the relevant sites had been closed for more than a year. This was a lie, bottom to top. The sites were actively operating as those words were spoken, and they weren't closed down until whistleblower James Bamford exposed the lie. https://theintercept.com/2014/10/02/the-nsa-and-me/

There's a list a mile long of similar stories. Court decisions, executive orders, and acts of Congress have bounced off these agencies without result.

I'd like to see examples, but I agree that you're not wrong in general. The agencies do respond to court decisions sometimes. My point is that when legal compliance is a coin flip and there's no way to check for results, you can't be sure that legal decision has changed anything at all.

Re: Grand jury subpoena for Signal user data

#239

Earlier quoted context omitted.

Exactly. This is why the fight to maintain gun rights is a never ending battle as well. Arming yourself with a gun is the best defense against a violent attacker. Legally enshrining that right is important. But even if we didn't have that right, we could still defend ourselves clandestinely via illegal means and home made weapons. Similarly when it comes to security, privacy, and anonymity the best defense is to arm…

> Arming yourself with a gun is the best defense against a violent attacker. Citation needed.

will these do?

https://www.nraila.org/articles/20150708/radical-anti-gun-gr...

http://www.naturalnews.com/047378_murder_sprees_armed_citize...

http://www.wsbtv.com/news/local/gwinnett-county/video-shows-...

"Best" might be hard to argue but it can be easily shown that you are better off having one when you need to defend yourself.

Re: Grand jury subpoena for Signal user data

#240
post #223

Earlier quoted context omitted.

Thanks for the reply. I 'feel' safer with the right to carry a gun. I can feel safer when everyone has a gun. Therefore morninj's argument does in fact also apply to guns. Anyone can feel a certain way about anything, which is why it is invalid when trying to construct a logically sound objective argument. A subjective premise can not lead us all to an objective conclusion.

But there are no objective conclusions in politics, and asking for such is shutting the door to any useful progress. Ideally, a good political solution is one where all involved parties "feel" that they have realized more of their demands than the others -- not one where one party gets all the spoils based on winning 51% of an artificial binary vote. I feel (part of) the reason your society is in political gridlock i…

The challenge I proposed is intended to be an objective exercise otherwise it's pointless because everyone can feel however they want.

Here are some examples of how both a gun and encryption can be used for the same end goal.

X can secure a financial transaction

X can stop a thief from obtaining my credit card information

X can stop someone from forcibly obtaining my identity

X can stop an attacker from obtaining private data stored in my home.

The only thing I've been able to think of that applies to encryption and does not apply to a gun is:

Encryption can verify that a message actually came from me by decrypting it using my public key.

This is objectively true for encryption and objectively false for a firearm. Also a firearm doesn't really help with anything on the internet except maybe a shady craigslist transaction in a dark parking lot. But I meant to imply that a realistic and suitable physical analogy can be applied.

Post reply on HN