Live data from Hacker News

Evidence that the FBI can hack into private Signal messages on a locked iPhone

forbes.com

141–150 of 243 posts

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#141

Earlier quoted context omitted.

You forgot a huge dimension of those jobs: As you get older, you are more valuable. No "silicon valley" syndrome about age: you'd never have to dye your hair, wear a hoodie to fit in, nobody will blink if you have to take a day off to take care of the kids. You can be a real adult - nobody comes into those programs and expects a ball pit or a foosball table, and nobody seriously thinks someone right out of college bu…

I know you're bring downvoted into oblivion for reverse ageism, but my experience mirrors your statements. I think the aggrieved HN masses just don't have similar, or much experience.

It's kind of bitterly ironic that on this site that comment is considered more inflammatory than someone like the top level commenter who effectively just says "lol only stupid people work for the government."

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#142
This seems to be problem with Signal to be honest.

AFAIK you can always use more secure data protection classes for your database[0]

They are using the default one, which is allowing AFU attack.

[0] https://support.apple.com/en-ca/guide/security/secb010e978a/...

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#143

Signal uses a sqlite database with an encryption extension for any long term storage of data. The key to this database is kept in whatever the phone uses for key storage. So if you break the phone you get everything including the old messages. The moral is to not keep the old messages around and delete them after you are done with them and hope they actually end up deleted. This is a hard problem simply because of th…

Actually this is not correct, you can also use key which is destroyed on lock.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#144

Earlier quoted context omitted.

This is why I keep a "universal hammer" at my desk. If the gov boys walk in all I have to do is use it on my phone / laptop. Problem solved. Thinking about upgrading to a small commercial grade shredder or microwave.

What are you doing such that those thoughts even cross your mind?

Such thoughts never cross yours?

I consider myself “recreationally paranoid”. I like to consider possible avenues of attack on me, and work out mitigations where possible. I’ve always considered it a subset of some people’s “hacker mindset”. The question of “How would I break into my stuff if I were motivated to, and what can I do to prevent it or make it more difficult to break?” provides me with a lot of satisfying thinking, even though I’m not planning to overthrow a government or move shipping containers of narcotics across borders.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#146
post #121

Earlier quoted context omitted.

I first saw that on BBS's, and it made it's way onto some forums in the early days of the web. I always found it humorous what laws they'd cite, when they bother to, to say basically "By clicking this button you assert you're not law enforcement officer".

Yeah it's a commonly held misconception spanning decades that cops must identify themselves if asked. I wonder where it originated. Needs some sunlight like: Badger: "Prove you're not a cop." ... Undercover cop: "If you ask a cop if he's a cop, he's like... obligated to tell you -- it's in the Constitution." - Breaking Bad, Season 2, Episode 8, moments before Badger gets arrested

I don’t think the server notices were based on this assumption. They were trying to use the draconian cyber security laws instituted after Mitnick and others got caught, which stipulated 10 years jail time for “unauthorised access to a computer system.”

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#147
post #68

Why would criminals not use expiring messages? Bizarre that you’d go to these lengths to use e2e chat and then not expire your messages after say an hour.

Because expiring/detonating messages are not valid security. Signal even warns of this: https://support.signal.org/hc/en-us/articles/360007320771-Se... If Charlie is selling drugs to Bob and Alice, expiring messages don't help Charlie out if the others are finding ways to capture data on the screen before the message expires (which, is very common for very innocent, non-malicious reasons). Similarly, though I've not…

Suppose I use a public key authentication scheme to communicate with a collaborator, Bob. To avoid any possible failures of technology, we've developed a simplified scheme that can be done with pencil and paper and sent through the mail. When Bob receives the message, he uses his private key to decrypt the message, writing each letter in the plaintext on a piece of paper so he can read it. After reading, he burns the paper completely with a small fire.

Are you going to insist that this last step, burning the plaintext copy, is not "valid security"? If you do, haven't we so mangled the meaning of security that it's not even intelligible any more?

I believe that "Let's not keep around unencrypted / minimally protected copies of our communications after we're done using them" is a perfectly valid security measure for two people to use. No, it doesn't solve "trust issues", in that one of them could simply refuse to delete the messages, but neither is it intended to.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#148

This seems to be problem with Signal to be honest. AFAIK you can always use more secure data protection classes for your database[0] They are using the default one, which is allowing AFU attack. [0] https://support.apple.com/en-ca/guide/security/secb010e978a/...

Would switching to say, Protected Unless Open have a negative performance impact? Otherwise, it seems like a kind of obvious oversight not to use a more restrictive data protection class. I'd be curious to know the Signal team's rationale for using PUFUA.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#149
post #28

If you own the phone, the messages are decrypted. This seems to be more about the phone access than anything to do with Signal, right?

Yes, nothing special - if someone else has your phone, it's not your phone anymore.

To be fair, Apple and Google both put a lot of effort into making exploiting a phone as difficult as they can even in the case of an attacker having physical possession.

I’d much rather have potential “evidence” against me on my phone, than on my laptop.

The stakes are very high though, and the attackers very motivated and well resourced, and I suspect there’s enough political pressure on them both to do only “a good enough job to make it look like they’re succeeding”. If anybody thinks the NSA isn’t several steps ahead of both Apple/Google and NSO/GreyKey, wtheyre fooling themselves...

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#150
post #84

Earlier quoted context omitted.

> It is NOT privacy focused. It’s not anonymity focused. If I want to have private conversations with friends, family or colleagues signal is fine.

Privacy encapsulates anonymity. Who you are talking to should be just as private as the contents of the message. Anonymity aids privacy.

Not sure I agree.

We expect heads of state to be able to have “private” discussions while knowing the other heads of state they may be communicating with. I can have “private” conversations with my partner, even though people know who that is.

You can also choose to anonymously communicate with no privacy, Reddit or 4chan style...

They may not be totally orthogonal, but I don’t think either privacy nor anonymity are encapsulated by each other.

Post reply on HN