Live data from Hacker News

Evidence that the FBI can hack into private Signal messages on a locked iPhone

forbes.com

61–70 of 243 posts

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#61

Earlier quoted context omitted.

First off, others have pointed out that these are 3rd party software companies providing the tools. I'd like to talk about your other point though: > I’ve never met a skilled developer willing to work for what the government pays So there are a lot of very skilled developers working for the government right now. I'd agree you probably haven't met them. I've found that people who work for the government, especially on…

You forgot a huge dimension of those jobs: As you get older, you are more valuable. No "silicon valley" syndrome about age: you'd never have to dye your hair, wear a hoodie to fit in, nobody will blink if you have to take a day off to take care of the kids. You can be a real adult - nobody comes into those programs and expects a ball pit or a foosball table, and nobody seriously thinks someone right out of college bu…

I appreciate your ability to walk into the middle of the bee hive to knock it over with this comment.

It was amusing to read and I don’t disagree with what you said but I don’t feel super qualified to judge either.

I’ve only seen that silicon valley start up culture from the outside when my partner worked at a YC company while they were going through a later stage fundraising round.

It wasn’t as cartoonish as you make it sound at all but your impression at least seemed in the ballpark of true.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#62

Universal encryption is a defense against blanket vacuuming of communications for later offline analysis. Its a defense against a massive parallel MITM attack against the world's communications infrastructure. Its not a defense against targeted attacks of individual devices.

In addition to this, I frequently hear people talk about how Signal would prevent monitoring of groups like those that stormed the capital. As if you can create a secret communication channel that members of the public can join but the FBI is unable to infiltrate. Signal and E2EE stop dragnets, not targeted efforts. Which honestly is exactly what I want and seems like what we want in a free and open society. Monitori…

> As if you can create a secret communication channel that members of the public can join but the FBI is unable to infiltrate.

Back in the day people used to, hilariously, have MOTD notices on all of their illegal servers saying the internet equivalent of "You have to tell me if you're a cop".

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#63
post #55

Earlier quoted context omitted.

Your understanding of baseband attacks is not correct. Having a baseband exploit would not facilitate this. Nor would exploits/backdoors in any particular app.

Why couldn't a baseband attack facilitate this? It was shown at least as far back as 2017[0] that a program on a baseband could affect the memory of the application processor, and in 2018[1] that a specially crafted message can achieve an RCE on a baseband. Since then, cell modems have gotten even more integrated with APs. [0] https://comsecuris.com/blog/posts/path_of_least_resistance/ [1] https://i.blackhat.com/us-1…

As far as I understand, the isolation between basebands and the main SoC has also been improved (using IOMMUs etc.)

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#64

Earlier quoted context omitted.

First off, others have pointed out that these are 3rd party software companies providing the tools. I'd like to talk about your other point though: > I’ve never met a skilled developer willing to work for what the government pays So there are a lot of very skilled developers working for the government right now. I'd agree you probably haven't met them. I've found that people who work for the government, especially on…

You forgot a huge dimension of those jobs: As you get older, you are more valuable. No "silicon valley" syndrome about age: you'd never have to dye your hair, wear a hoodie to fit in, nobody will blink if you have to take a day off to take care of the kids. You can be a real adult - nobody comes into those programs and expects a ball pit or a foosball table, and nobody seriously thinks someone right out of college bu…

I know you're bring downvoted into oblivion for reverse ageism, but my experience mirrors your statements. I think the aggrieved HN masses just don't have similar, or much experience.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#65

Universal encryption is a defense against blanket vacuuming of communications for later offline analysis. Its a defense against a massive parallel MITM attack against the world's communications infrastructure. Its not a defense against targeted attacks of individual devices.

In addition to this, I frequently hear people talk about how Signal would prevent monitoring of groups like those that stormed the capital. As if you can create a secret communication channel that members of the public can join but the FBI is unable to infiltrate. Signal and E2EE stop dragnets, not targeted efforts. Which honestly is exactly what I want and seems like what we want in a free and open society. Monitori…

> Monitoring shouldn't be the default but only happen when there is a warranted reason to monitor, preferable with a literal warrant.

In many cases, well-done E2EE like Signal stops dragnets and targeted efforts. Even with a literal warrant.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#66

I hate be a spoil sport, but generally I don't need protection from the FBI, NSA, CIA. I need convenience to unlock my phone/laptop quickly with a fingerprint, even after a restart. XKCD nails this: https://xkcd.com/538 I'm MOST concerned with Google/Facebook continuously circumventing laws and violating my opt-out preferences. I'd like to have a null advertising ID for instance. Can't do that. And besides, you don't…

I hate be a spoil sport, but generally I don't need protection from the FBI, NSA, CIA.

Awesome. Good for you. However, there are people out there who are busy changing the world, holding the powerful to account, and generally being involved in society in ways that are less safe and more interesting than you do. This is about them, not about you.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#67
post #43
post #32

Earlier quoted context omitted.

Maybe your assumption that something dubious is going on can be eliminated by Occam's razor? Because: any business that gains in popularity will automatically also see higher press coverage.

Just like women in tech — or any male dominated industries — have proportionately more unfortunate encounters with men because each woman has more men around her to begin with?

Where is the data that “women specifically in tech have more unfortunate encounters with men” than other industries?

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#68

Why would criminals not use expiring messages? Bizarre that you’d go to these lengths to use e2e chat and then not expire your messages after say an hour.

Because expiring/detonating messages are not valid security. Signal even warns of this:

https://support.signal.org/hc/en-us/articles/360007320771-Se...

If Charlie is selling drugs to Bob and Alice, expiring messages don't help Charlie out if the others are finding ways to capture data on the screen before the message expires (which, is very common for very innocent, non-malicious reasons).

Similarly, though I've not tested this with signal specifically, other chat apps' implementations of expired messages can be futzed with by simply disconnecting the phone from all network connections.

People who need true privacy, regardless of the reason, aren't using chat apps readily available from stores since the apps only prevent passive snooping, they do nothing to help establish circles of trust. Such business is either conducted out in the open without concern for who sees what (you can see this in countless pictures online when people openly sell stuff like weed), or such business stays off chat apps completely because there's no way to validate who is holding the phone on the other end. The transactions occur indirectly using proven safe methods for the courier and buyer (dead drops, mail tricks, etc)

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#69

That’s why a sane person should’t trust any messenger, especially if it works in android/iOS/Windows. And Signal specifically works like a red flag for monitoring software- this user has something to hide!

> And Signal specifically works like a red flag for monitoring software- this user has something to hide!

Less accurate though with every new user.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#70

If you own the phone, the messages are decrypted. This seems to be more about the phone access than anything to do with Signal, right?

This should bring into question even more Signal's implementation of using real phone numbers for accounts. It is NOT privacy focused.

Even if this 'hackability' is an issue only with the security of the phone/hardware - able to be hacked and thus reach the decrypted signal messages - That also means, that person's Signal contacts also have their real identities exposed. (Where they wouldn't be if the account names/ids could be arbitrary like eg. wickr)

Post reply on HN