Live data from Hacker News

Evidence that the FBI can hack into private Signal messages on a locked iPhone

forbes.com

191–200 of 243 posts

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#191

Earlier quoted context omitted.

Yes it does, since it's not presented as factual.

It's written as a statement, not as a figure of speech. If it's not intended to be factual, it should be annotated as such. It literally claims theft as it stands, which makes the article seem juvenile in use of language.

It's not written as a "statement [of fact]", that is incorrect.

How did 'beervirus and I know how to interpret the phrase successfully?

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#192
post #28

If you own the phone, the messages are decrypted. This seems to be more about the phone access than anything to do with Signal, right?

Yes, nothing special - if someone else has your phone, it's not your phone anymore.

Does Signal not encrypt its DBs when not in use and upon shutdown?

Edit: it seems that Signal uses db protection but in a way that fails for a cracked phone like this (?): https://news.ycombinator.com/item?id=26096778

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#193

Earlier quoted context omitted.

> I frequently hear people talk about how Signal would prevent monitoring of groups like those that stormed the capital Those folks walked over on public roads from a Trump rally down the street, live streaming on a hundred cameras as they did it. Of all the things that went wrong on the 6th, surveillance was clearly not one of them. What I think you're remembering is more the point that Signal and Telegram provide h…

> Q communities on Facebook and Twitter made it easy to see where these people were coming from. Cynical view. Those made it easy to see what the manipulated fairly public mass of disenfranchised or disgruntled or actively evil Q/Trump supporters were discussing and planning. I’ll bet people like flexcuff guy and pipebomb guy weren’t discussing _their_ plans in such public forums. And I’ll bet there was a _lot_ of pl…

> I’ll bet people like flexcuff guy and pipebomb guy weren’t discussing _their_ plans in such public forums.

I dunno, some of those folks were pretty brazen. Remember they thought all this was, if not "legal" exactly, "sanctioned" by their sitting president. They weren't trying to hide.

But even if we grant that the premise (which is clearly true) that serious criminals will always have the ability to hide from surveillance, the presence of an easily found public forum is still a prerequisite for real insurrection.

Flexcuff guy and pipebomb guy may have been hardened experts, but they couldn't have sacked the capitol with only their militias behind them. The preventable part of this is the mob violence. And mob violence requires a mob, which requires that the members of the mob (by definition amateurs) be able to find forums to radicalize them.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#194

An interesting idea for an app which resets the iPhone after some idle time, or if iPhone loses contact with the apple watch. To prevent AFU exploits.

The Signal app, to the best of my understanding, does have a built in dead man's switch in the form of the PIN system. You can apparently set the time range in the settings.

Signal PIN currently serves a different purpose: it enables registration lock, which is a defense against number porting attacks. https://support.signal.org/hc/en-us/articles/360007059792-Si...

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#195

Earlier quoted context omitted.

Would switching to say, Protected Unless Open have a negative performance impact? Otherwise, it seems like a kind of obvious oversight not to use a more restrictive data protection class. I'd be curious to know the Signal team's rationale for using PUFUA.

Actually i just checked their entitlements on github and it is set to NSFileProtectionComplete. Seems stranger than I thought edit: After diving into code, they are using NSFileProtectionCompleteUntilFirstUserAuthentication for their DB file, probably they have some reason

So useless for a stolen cracked phone like this case?

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#196

Earlier quoted context omitted.

> As if you can create a secret communication channel that members of the public can join but the FBI is unable to infiltrate. Back in the day people used to, hilariously, have MOTD notices on all of their illegal servers saying the internet equivalent of "You have to tell me if you're a cop".

I first saw that on BBS's, and it made it's way onto some forums in the early days of the web. I always found it humorous what laws they'd cite, when they bother to, to say basically "By clicking this button you assert you're not law enforcement officer".

Total guess: I assume they could claim unauthorized access to a computer system under the CFAA.

I’m fairly sure that the police can’t hack a random server then claim “I’m a cop so it’s okay” without a warrant. At the very least any evidence gathered may be deemed inadmissible. Accessing a system without permission may, I guess, fall in the same bucket.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#197
post #186

I wonder if Apple's relentless march towards eliminating all physical ports on the phone is at least in some small part an attempt to harden against these GrayKey / Cellebrite tools that can attack the phone. I am not particularly familiar with them, but having previously been someone who jailbroke my phone, several of the exploits used were originally delivered via plugging the phone in to another device, i.e. throu…

That would be very interesting indeed. I never thought of that!

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#199
post #50
post #7

How is it possible that the FBI has so much advanced stuff when I’ve never met a skilled developer willing to work for what the government pays? Are their tools developed by high paid contractors?

> I’ve never met a skilled developer willing to work for what the government pays? Is that your bubble that's poorly skilled?

It’s just reality. The vast majority of skilled developers will take a $450k job in SV over a $100k government job.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#200
post #167
post #146

Earlier quoted context omitted.

I don’t think the server notices were based on this assumption. They were trying to use the draconian cyber security laws instituted after Mitnick and others got caught, which stipulated 10 years jail time for “unauthorised access to a computer system.”

Not a lawyer, but I seriously doubt any prosecutor would bring a criminal case against a law enforcement officer whose access to a system was denied for being a law enforcement officer , and while there are some situations where one can make a civil claim under the CFAA, what legitimate damages could you show that an officer caused you by accessing your site in the furtherance of their duty? If someone actually tried…

It’s not about bringing a criminal case, it’s about being able to say “this evidence was gathered illegally” if it was gathered without a warrant, then having the evidence thrown out.

A defense lawyer may give something like that a shot at least.

I have no idea if it would work in practice of course.

Post reply on HN