Live data from Hacker News

Evidence that the FBI can hack into private Signal messages on a locked iPhone

forbes.com

131–140 of 243 posts

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#131

Universal encryption is a defense against blanket vacuuming of communications for later offline analysis. Its a defense against a massive parallel MITM attack against the world's communications infrastructure. Its not a defense against targeted attacks of individual devices.

If you are really paranoid you'd also worry about future attacks revealed through algorithmic flaws, quantum computing, or simple increases in processing power.

I guess our hope is that they won't care what we said after a decade or two.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#132
But would it do that and admit that when it's not really worth? Din't you have to be really really notorious for them to use this kind of evidence in a court? If I were them and could decrypt something I would prefer to keep this fact secret.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#133

An interesting idea for an app which resets the iPhone after some idle time, or if iPhone loses contact with the apple watch. To prevent AFU exploits.

The Signal app, to the best of my understanding, does have a built in dead man's switch in the form of the PIN system. You can apparently set the time range in the settings.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#136
Signal uses a sqlite database with an encryption extension for any long term storage of data. The key to this database is kept in whatever the phone uses for key storage. So if you break the phone you get everything including the old messages. The moral is to not keep the old messages around and delete them after you are done with them and hope they actually end up deleted.

This is a hard problem simply because of the medium. If you do encrypted instant messaging you need to have everything fairly exposed all the time. You simply can't make it as secure as something like encrypted email where you can lock down everything very strongly and only unlock it when you are in a safe environment. The extra level of security also means that keeping the old messages around is a lot less risky.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#137

Earlier quoted context omitted.

My understanding is that the phone number is never even sent to Signal in the first place. So doing so would result in a git commit.

Is there an audit trail showing that the compiled binary available in the App store is the same one you build from source?

Sadly, no.

There’s still some “trust” required in both Whispersystems to not backdoor updates, as well as Apple and Google to not backdoor the distributed apps after Whispersystems submit updates for publication.

There is though, some ability for skilled enough people to “trust but verify” by reversing the app bundles after publication. I believe (but not for any good evidence based reason) that there are “enough eyeballs” interested in Signal that _hopefully_ if a backdoored app update ever appears the white hats will raise the alarm quickly (I have no doubt the black hats will sell the details to NSO/GreyKey just as quickly...)

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#138

Earlier quoted context omitted.

In addition to this, I frequently hear people talk about how Signal would prevent monitoring of groups like those that stormed the capital. As if you can create a secret communication channel that members of the public can join but the FBI is unable to infiltrate. Signal and E2EE stop dragnets, not targeted efforts. Which honestly is exactly what I want and seems like what we want in a free and open society. Monitori…

Fun fact for the UK: "UK police have a new tactic to circumvent strong iPhone encryption: steal the unlocked phone out of the criminal’s hand" ( https://9to5mac.com/2016/12/05/uk-police-have-a-new-tactic-f... ) I remember reading this a few years back. The title says it all. Why bother cracking codes etc when you can get a judge to sign THAT for you? :) Going through the PDF of the legal document, on page 10, the scr…

To defend against on-device attacks or iCloud backups, Telegram would need to do its own, separate encryption of its storage and prompt the user for a passphrase at app launch.

The typical security model for iOS apps assumes that the local device is secure, as its storage is already encrypted by the system based on its passcode/biometrics (on initial power-up biometrics aren't available).

End-to-end encryption within chat apps typically refers to encryption over the network. It does not include encryption of messages once they reach their intended recipients.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#139

Earlier quoted context omitted.

Yes. But note that Signal doesn't know your number. Usernames are being promised this year too.

> But note that Signal doesn't know your number Courts can compel them to keep these records, and require them to not disclose to their customers that they are doing so.

At least Apple have demonstrated pushing back on a court order requiring them to fundamentally break their product’s advertised security to comply with such an order.

I’d be curious to see if WhisperSystems are prepared enough to lawyer up and fight like that. (I suspect they’d probably get NSLed like Lavabit did we won’t know about it until way later...)

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#140
post #7

How is it possible that the FBI has so much advanced stuff when I’ve never met a skilled developer willing to work for what the government pays? Are their tools developed by high paid contractors?

First off, others have pointed out that these are 3rd party software companies providing the tools. I'd like to talk about your other point though: > I’ve never met a skilled developer willing to work for what the government pays So there are a lot of very skilled developers working for the government right now. I'd agree you probably haven't met them. I've found that people who work for the government, especially on…

From what I've heard, the hours you cite also enable moonlighting. Some people do a few hours a night and make as much as their day job. Sometimes it's even as a contractor in a related field that might service their main role. At least they're getting paid for this "overtime"!
Post reply on HN