Live data from Hacker News

Evidence that the FBI can hack into private Signal messages on a locked iPhone

forbes.com

121–130 of 243 posts

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#121

Earlier quoted context omitted.

> As if you can create a secret communication channel that members of the public can join but the FBI is unable to infiltrate. Back in the day people used to, hilariously, have MOTD notices on all of their illegal servers saying the internet equivalent of "You have to tell me if you're a cop".

I first saw that on BBS's, and it made it's way onto some forums in the early days of the web. I always found it humorous what laws they'd cite, when they bother to, to say basically "By clicking this button you assert you're not law enforcement officer".

Yeah it's a commonly held misconception spanning decades that cops must identify themselves if asked. I wonder where it originated. Needs some sunlight like:

  Badger: "Prove you're not a cop."
  ...
  Undercover cop: "If you ask a cop if he's a cop, he's like... obligated to tell you -- it's in the Constitution."
- Breaking Bad, Season 2, Episode 8, moments before Badger gets arrested

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#122
post #65

Earlier quoted context omitted.

> Monitoring shouldn't be the default but only happen when there is a warranted reason to monitor, preferable with a literal warrant. In many cases, well-done E2EE like Signal stops dragnets and targeted efforts. Even with a literal warrant.

I'm not sure I buy this, but it depends how we define targeted attacks. If we include getting access to the device, which I think is reasonable, it obviously doesn't stop targeted efforts. Not to say it doesn't make it more difficult. Remotely, are we only talking Signal or the system as a whole? AFAIK nothing is unhackable, only difficult to hack. But as long as we're playing the cat and mouse game I'm happy. Improv…

My personal perspective is that if a Three Letter Agency becomes specifically “interested” in me, I’m fucked. No matter what I do. Even if I fake my own death and live in a submarine...

What I can do, however, is take measures to protect myself against less powerful or sophisticated attackers.

Where I come from, “communications metadata” is required to be kept by all telcos and isps. This metadata is them “available to law enforcement” - which is not just investigations into child abuse and drug running, as the proponents of the laws made out when advocating for them, but includes agencies such as the Taxi commission, various local councils, and state fisheries departments.

https://www.theregister.com/AMP/2018/11/14/comms_alliance_me...

Using (trusted) vpns and e2e encrypted messaging will reduce the chance of a local council or a fisheries inspector being able to get as much information from my metadata as they might from non VPN and secure messaging using people.

(Of course, it might backfire and just paint a big target on my back... One potential privacy advantage of COVID and widespread wfh is that many many more people are using VPN tunnels for ordinary and mundane purposes. Adding extra hay to the haystack my needle is trying to hide in is a good thing. So long as it’s not Mossad looking for my specific needle...)

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#123

Universal encryption is a defense against blanket vacuuming of communications for later offline analysis. Its a defense against a massive parallel MITM attack against the world's communications infrastructure. Its not a defense against targeted attacks of individual devices.

Lots of DLP solutions rely on MITM user sessions, so at least corps who implement those solutions have access to all their user data in the clear —which is fair for a Corp. but users not being hygienic about their data often use Corp resources for personal use and that can get vacuumed up in the process.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#125

If you own the phone, the messages are decrypted. This seems to be more about the phone access than anything to do with Signal, right?

The iPhone's terrible battery life isn't a bug, it's a privacy feature! I wonder if the FBI's evidence protocol involves immediately plugging in an iPhone to maintain the vulnerable state: > That latter acronym stands for “after first unlock” and describes an iPhone in a certain state: an iPhone that is locked but that has been unlocked once and not turned off. An iPhone in this state is more susceptible to having da…

One thing they did do: if you bring up the power off screen (by holding power, or power+volume up, depending on model) then it disables biometric unlock, even if you don't power it off. Bringing up the power off slider screen is sufficient to force a passcode-only unlock.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#126
post #120

Earlier quoted context omitted.

> Problem solved. Now you have a new problem: Destruction of evidence.

IANAL, but my understanding is that obstruction of justice via spoliation, tampering, or destruction of evidence is a charge that requires your investigation to have already begun, the raid to have already started, or the arrest to have been made, and that you are free to destroy any of your own property prior to these events. Specifically, you need to knowingly be the subject of an investigation. I'd assume destroyi…

Smashing things in response to "the govt boys" walking in sounds like it would count, no?

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#127

Earlier quoted context omitted.

In addition to this, I frequently hear people talk about how Signal would prevent monitoring of groups like those that stormed the capital. As if you can create a secret communication channel that members of the public can join but the FBI is unable to infiltrate. Signal and E2EE stop dragnets, not targeted efforts. Which honestly is exactly what I want and seems like what we want in a free and open society. Monitori…

> I frequently hear people talk about how Signal would prevent monitoring of groups like those that stormed the capital Those folks walked over on public roads from a Trump rally down the street, live streaming on a hundred cameras as they did it. Of all the things that went wrong on the 6th, surveillance was clearly not one of them. What I think you're remembering is more the point that Signal and Telegram provide h…

> Q communities on Facebook and Twitter made it easy to see where these people were coming from.

Cynical view. Those made it easy to see what the manipulated fairly public mass of disenfranchised or disgruntled or actively evil Q/Trump supporters were discussing and planning. I’ll bet people like flexcuff guy and pipebomb guy weren’t discussing _their_ plans in such public forums. And I’ll bet there was a _lot_ of planning of the sort that used to take place in underground-public places like 4chan, which has now gone deeper underground and has much more stringent initiation rites for admitting new members. The sort of planning that involves manipulating and convincing “pawns” in their “it’s all about ethics in video game journalism” games to provide cover and take the fall for deeply serious shit...

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#128
post #120

Earlier quoted context omitted.

> Problem solved. Now you have a new problem: Destruction of evidence.

IANAL, but my understanding is that obstruction of justice via spoliation, tampering, or destruction of evidence is a charge that requires your investigation to have already begun, the raid to have already started, or the arrest to have been made, and that you are free to destroy any of your own property prior to these events. Specifically, you need to knowingly be the subject of an investigation. I'd assume destroyi…

I suspect that a judge/jury would not be sympathetic to a complaint along the lines of:

"I had no idea I would be under investigation when I saw the cops arriving at the door. I just decided it'd be fun to beat the shit out of my laptop with a hammer at that exact moment."

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#129
post #124

After holding down the power and volume buttons on an iPhone, biometrics will not work, and the phone will require a passcode. Does this still count as AFU?

I think a better fix for this issue (because, of course, they can seize the other party's phone) is to use Signal's expiring/disappearing messages, so that they are (presumably) erased from both devices after the specified period of time.

I wonder if the method of "disappearing" the messages used by the app is vulnerable to forensic analysis or not.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#130

Earlier quoted context omitted.

I'm not sure I buy this, but it depends how we define targeted attacks. If we include getting access to the device, which I think is reasonable, it obviously doesn't stop targeted efforts. Not to say it doesn't make it more difficult. Remotely, are we only talking Signal or the system as a whole? AFAIK nothing is unhackable, only difficult to hack. But as long as we're playing the cat and mouse game I'm happy. Improv…

My personal perspective is that if a Three Letter Agency becomes specifically “interested” in me, I’m fucked. No matter what I do. Even if I fake my own death and live in a submarine... What I can do, however, is take measures to protect myself against less powerful or sophisticated attackers. Where I come from, “communications metadata” is required to be kept by all telcos and isps. This metadata is them “available…

[deleted]
Post reply on HN