Live data from Hacker News

Hong Kong protestors using Bridgefy's Bluetooth-based mesh network messaging app

forbes.com

151–160 of 221 posts

Re: Hong Kong protestors using Bridgefy's Bluetooth-based mesh network messaging app

#151
post #128

Earlier quoted context omitted.

I think China getting that information from Apple is sort of a second-order concern at this point. In a more stable situation, yeah, you don't want the police to have a reason to knock on your door. When you're gearing up to go protest in public and the cops are dropping tear gas on everybody, those sorts of lists are less important. Not saying that it doesn't matter, but there is no such thing as absolute security,…

Keep in mind that Apple's iCloud services in China are not actually provided by Apple. They are provided by Cloud Big Data Industrial Development Co., Ltd., and allows Apple to, "continue to improve iCloud services in China mainland and comply with Chinese regulations". [0] This service even has different terms of service, than the standard iCloud offering (though I haven't done a diff to see what's changed). The eff…

Anybody have some details on this? I always wondered how this is handled for Chinese going abroad or Foreigners traveling in China without sending the keys back and forth.

Or do Chinese iCloud accounts still use the Chinese servers even when abroad while the western ones get to go through the great firewall for western iCloud?

Re: Hong Kong protestors using Bridgefy's Bluetooth-based mesh network messaging app

#153
post #112
post #87

Earlier quoted context omitted.

this is why you remove the battery of the burner until you use it. remove the battery and sim of your compromised phone relocate yourself install sim and battery of your burner

This still creates a detectable pattern. If the legit phone goes off while the burner is on that's a pattern. If the legit phone goes off and (travel time / distance) elapses before burner appears (travel time / distance) away from the last legit ping that's a pattern. If the legit phone and burner phone hit the same towers at the same time more than 3 times that's a pattern. If the burner phone spends most of the ti…

If you think it's bad now, wait until 5G rolls out allowing live tracking of people to within meters.

Re: Hong Kong protestors using Bridgefy's Bluetooth-based mesh network messaging app

#154

Earlier quoted context omitted.

Xcode is able to dynamically generate a development provisioning profile, even if you do not have a (paid) developer account. So side-loading is definitely possible, in some respects.

Unable to reply to Illniyar’s comment below. To add to those points on the difficulty (actually practical impossibility), you’d also need to have access to a Mac to do all those things every seven days. That’s a very big ask, along with the technical know how to use Xcode, for so many people in Hong Kong.

Does anyone know the reason(s) why Apple makes it impractical to sideload?

Re: Hong Kong protestors using Bridgefy's Bluetooth-based mesh network messaging app

#155

Earlier quoted context omitted.

I used a simple mobile "burner" and was fine to authenticate. I bought bunch of $5 cards with cash in a small store and used this one in my dumb flip phone bought on a flea market few months ago. I am certain to a high degree that's pretty enough setup to stay under radar.

You can't get "burner" SIMs in Australia (where I am), I don't think. They usually require a sign up before activation; I'd be interested to know of ones that are true "burner" SIMs that are sold here.

The ID verification methods vary to account for channels like that you can buy SIMs from vending machines at airports and train stations and verify online https://www.acma.gov.au/theACMA/approved-methods-for-verific...

Vodafone just let you tick a box saying "i am who i say i am" https://www.acma.gov.au/Industry/Telco/Carriers-and-service-...

Re: Hong Kong protestors using Bridgefy's Bluetooth-based mesh network messaging app

#156
post #128

Earlier quoted context omitted.

3) I think the worry is China forcing Apple to produce this info (list of HK users with said app installed), not what Apple themselves would do with it. Maybe not a dealbreaker, but something to consider...

I think China getting that information from Apple is sort of a second-order concern at this point. In a more stable situation, yeah, you don't want the police to have a reason to knock on your door. When you're gearing up to go protest in public and the cops are dropping tear gas on everybody, those sorts of lists are less important. Not saying that it doesn't matter, but there is no such thing as absolute security,…

I disagree, hiding behind the anonymity of the crowd is critical in protests. Yes, they might catch a few people, but if you know for sure they'll just round everyone up later because they know exactly who was protesting, suddenly nobody wants to do it.

Re: Hong Kong protestors using Bridgefy's Bluetooth-based mesh network messaging app

#157

Earlier quoted context omitted.

Or join as a malicious node. There is no panacea without control over some infrastructure.

If they were doing E2E encryption, that would not be a problem. Broadcasting to find the right recipient (the one with the decrypting key) but contents protected from everybody else.

Ok so how would key distribution work here? Tofu?

Re: Hong Kong protestors using Bridgefy's Bluetooth-based mesh network messaging app

#158
post #154

Earlier quoted context omitted.

Unable to reply to Illniyar’s comment below. To add to those points on the difficulty (actually practical impossibility), you’d also need to have access to a Mac to do all those things every seven days. That’s a very big ask, along with the technical know how to use Xcode, for so many people in Hong Kong.

Does anyone know the reason(s) why Apple makes it impractical to sideload?

Side loading is a threat to Apples control over all iOS and similar AppStore devices. If I didn’t want to comply with the very far-reaching requirements for e g in-app stores, I could just ask my users to side load my app. If for example Audible did this, it’d be a real threat.

Re: Hong Kong protestors using Bridgefy's Bluetooth-based mesh network messaging app

#160

No closed source mesh networking can be secure. However good user experience it has. They are no different than using WhatsApp. Indeed in that respect at least Signal is better. I am not sure why protestors did not adopt the open source serval mesh project apk and ios app. [1] In Hong Kong given the density of building it's bit hard to have a line of sight, so it will still be hard to build a local network. But it's…

I’d prefer anonymity over security.
Post reply on HN