Live data from Hacker News

Evidence that the FBI can hack into private Signal messages on a locked iPhone

forbes.com

101–110 of 243 posts

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#101
post #84

Earlier quoted context omitted.

This should bring into question even more Signal's implementation of using real phone numbers for accounts. It is NOT privacy focused. Even if this 'hackability' is an issue only with the security of the phone/hardware - able to be hacked and thus reach the decrypted signal messages - That also means, that person's Signal contacts also have their real identities exposed. (Where they wouldn't be if the account names/i…

> It is NOT privacy focused. It’s not anonymity focused. If I want to have private conversations with friends, family or colleagues signal is fine.

Privacy encapsulates anonymity. Who you are talking to should be just as private as the contents of the message. Anonymity aids privacy.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#102

Earlier quoted context omitted.

In addition to this, I frequently hear people talk about how Signal would prevent monitoring of groups like those that stormed the capital. As if you can create a secret communication channel that members of the public can join but the FBI is unable to infiltrate. Signal and E2EE stop dragnets, not targeted efforts. Which honestly is exactly what I want and seems like what we want in a free and open society. Monitori…

> As if you can create a secret communication channel that members of the public can join but the FBI is unable to infiltrate. Back in the day people used to, hilariously, have MOTD notices on all of their illegal servers saying the internet equivalent of "You have to tell me if you're a cop".

[deleted]

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#103

Earlier quoted context omitted.

In addition to this, I frequently hear people talk about how Signal would prevent monitoring of groups like those that stormed the capital. As if you can create a secret communication channel that members of the public can join but the FBI is unable to infiltrate. Signal and E2EE stop dragnets, not targeted efforts. Which honestly is exactly what I want and seems like what we want in a free and open society. Monitori…

> As if you can create a secret communication channel that members of the public can join but the FBI is unable to infiltrate. Back in the day people used to, hilariously, have MOTD notices on all of their illegal servers saying the internet equivalent of "You have to tell me if you're a cop".

I first saw that on BBS's, and it made it's way onto some forums in the early days of the web.

I always found it humorous what laws they'd cite, when they bother to, to say basically "By clicking this button you assert you're not law enforcement officer".

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#104

If you own the phone, the messages are decrypted. This seems to be more about the phone access than anything to do with Signal, right?

Soon we will have an article about "If you use Signal to talk to your mother, FBI can see your messages if your mother send them to them"

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#105
post #59

Rather than hacking Signal itself, maybe they were able to access the iOS app preview files from the iOS app-switcher? I'd imagine the app-switcher (the feature when you swipe up to switch between recently used apps) works by overwriting a screenshot every time it's minimized. Maybe they were able to access this data directly or indirectly (or maybe even via iCloud). There's a setting in Signal where you can hide the…

Should read the article before you comment next time ;)

There is a screenshot in there showing it is directly parsing the Signal sqlite database. I am guessing on his device he had not set an access passcode to the Signal app so no key was required to decrypt the local message cache. Towards the end of the article the Signal creator hit the nail on the head saying this is a phone security issue and nothing to do with Signals security.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#106

Earlier quoted context omitted.

> But note that Signal doesn't know your number Courts can compel them to keep these records, and require them to not disclose to their customers that they are doing so.

My understanding is that the phone number is never even sent to Signal in the first place. So doing so would result in a git commit.

Assuming the published app matches the published source.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#107

Universal encryption is a defense against blanket vacuuming of communications for later offline analysis. Its a defense against a massive parallel MITM attack against the world's communications infrastructure. Its not a defense against targeted attacks of individual devices.

This is why I keep a "universal hammer" at my desk. If the gov boys walk in all I have to do is use it on my phone / laptop. Problem solved. Thinking about upgrading to a small commercial grade shredder or microwave.

I'm not sure if you're kidding, but smashing your devices with a hammer will not damage the cold storage unless you directly hit it and sufficiently deform it. It's much more likely that you just damage the screen, casing and mainboard when randomly smashing on it. Especially with a laptop. So the storage could simply be ported to an undamaged phone/laptop and effectively all you achieved is turning the device off.

Similarly with a microwave. The reflections and sparks might kill the microwave before the hard drive in your device is actually damaged. Please correct me if im wrong, but the microwaves shouldn't actually be able to flip the bits, but just heat up the material.

A shredder strong enough to tear the metal/silicon/plastic apart in small enough pieces sounds reliable.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#108

Earlier quoted context omitted.

> But note that Signal doesn't know your number Courts can compel them to keep these records, and require them to not disclose to their customers that they are doing so.

My understanding is that the phone number is never even sent to Signal in the first place. So doing so would result in a git commit.

Is there an audit trail showing that the compiled binary available in the App store is the same one you build from source?

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#109

Universal encryption is a defense against blanket vacuuming of communications for later offline analysis. Its a defense against a massive parallel MITM attack against the world's communications infrastructure. Its not a defense against targeted attacks of individual devices.

This is why I keep a "universal hammer" at my desk. If the gov boys walk in all I have to do is use it on my phone / laptop. Problem solved. Thinking about upgrading to a small commercial grade shredder or microwave.

> Problem solved.

Now you have a new problem: Destruction of evidence.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#110

Earlier quoted context omitted.

In addition to this, I frequently hear people talk about how Signal would prevent monitoring of groups like those that stormed the capital. As if you can create a secret communication channel that members of the public can join but the FBI is unable to infiltrate. Signal and E2EE stop dragnets, not targeted efforts. Which honestly is exactly what I want and seems like what we want in a free and open society. Monitori…

> As if you can create a secret communication channel that members of the public can join but the FBI is unable to infiltrate. Back in the day people used to, hilariously, have MOTD notices on all of their illegal servers saying the internet equivalent of "You have to tell me if you're a cop".

[deleted]
Post reply on HN