Live data from Hacker News

Evidence that the FBI can hack into private Signal messages on a locked iPhone

forbes.com

221–230 of 243 posts

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#221
post #76

Earlier quoted context omitted.

I know you're bring downvoted into oblivion for reverse ageism, but my experience mirrors your statements. I think the aggrieved HN masses just don't have similar, or much experience.

+1. Also upvoting the original comment because no one seems to be disagreeing with it with any words. Solving really hard problems is valuable. Little gets easier, but you can get better at it. You have me wondering .. Does expertise from experience (whether compressed into a few years or a lot) qualify as reverse ageism? Is anyone being excluded or denigrated? It seems plausible (but not exclusively) that the more t…

"Does expertise from experience (whether compressed into a few years or a lot) qualify as reverse ageism? Is anyone being excluded or denigrated?"

No, of course not - isn't it silly that we have to ask if that is "reverse ageism" to say that people who spend time at something are generally better at it? That's universally true of every single human endeavor, isn't it?

"It seems plausible (but not exclusively) that the more time and effort you apply to something, the better you will probably get at it." - Why does it sound like you're shying away from stating something that should be immediately obvious to every single person? Is it because you're afraid of the charge of reverse ageism if you agree? If so...isn't that silly?

"It seems plausible (but not exclusively) that the more time and effort you apply to something, the better you will probably get at it. Time alone isn’t a measure of experience and expertise but it doesn’t hurt." - I agree wholeheartedly - again, I thought that was obvious.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#222

Earlier quoted context omitted.

To defend against on-device attacks or iCloud backups, Telegram would need to do its own, separate encryption of its storage and prompt the user for a passphrase at app launch. The typical security model for iOS apps assumes that the local device is secure, as its storage is already encrypted by the system based on its passcode/biometrics (on initial power-up biometrics aren't available). End-to-end encryption within…

> To defend against on-device attacks or iCloud backups, Telegram would need to do its own, separate encryption of its storage and prompt the user for a passphrase at app launch. This isn’t quite correct. iOS applications can exclude files from iCloud backups.

This would still fail to preclude an on-device attack.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#223

Earlier quoted context omitted.

Would switching to say, Protected Unless Open have a negative performance impact? Otherwise, it seems like a kind of obvious oversight not to use a more restrictive data protection class. I'd be curious to know the Signal team's rationale for using PUFUA.

Actually i just checked their entitlements on github and it is set to NSFileProtectionComplete. Seems stranger than I thought edit: After diving into code, they are using NSFileProtectionCompleteUntilFirstUserAuthentication for their DB file, probably they have some reason

Presumably it lets things like notifications work.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#224

Earlier quoted context omitted.

What are you doing such that those thoughts even cross your mind?

Such thoughts never cross yours? I consider myself “recreationally paranoid”. I like to consider possible avenues of attack on me, and work out mitigations where possible. I’ve always considered it a subset of some people’s “hacker mindset”. The question of “How would I break into my stuff if I were motivated to, and what can I do to prevent it or make it more difficult to break?” provides me with a lot of satisfying…

Thermite. Piezo ignition. Bonus points for using a Raspberry Pi gpio to do it from a crafted SMS.

Do keep a fire extinguisher in the room below though, it's more effective than you think.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#225

Earlier quoted context omitted.

In addition to this, I frequently hear people talk about how Signal would prevent monitoring of groups like those that stormed the capital. As if you can create a secret communication channel that members of the public can join but the FBI is unable to infiltrate. Signal and E2EE stop dragnets, not targeted efforts. Which honestly is exactly what I want and seems like what we want in a free and open society. Monitori…

> As if you can create a secret communication channel that members of the public can join but the FBI is unable to infiltrate. Back in the day people used to, hilariously, have MOTD notices on all of their illegal servers saying the internet equivalent of "You have to tell me if you're a cop".

We laugh now, but plenty of people believe in Warrant Canaries...

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#226

Earlier quoted context omitted.

You forgot a huge dimension of those jobs: As you get older, you are more valuable. No "silicon valley" syndrome about age: you'd never have to dye your hair, wear a hoodie to fit in, nobody will blink if you have to take a day off to take care of the kids. You can be a real adult - nobody comes into those programs and expects a ball pit or a foosball table, and nobody seriously thinks someone right out of college bu…

I know you're bring downvoted into oblivion for reverse ageism, but my experience mirrors your statements. I think the aggrieved HN masses just don't have similar, or much experience.

If you landed on "they don't have much experience", they'll probably get there, it will just take a few more years...

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#227
post #186

I wonder if Apple's relentless march towards eliminating all physical ports on the phone is at least in some small part an attempt to harden against these GrayKey / Cellebrite tools that can attack the phone. I am not particularly familiar with them, but having previously been someone who jailbroke my phone, several of the exploits used were originally delivered via plugging the phone in to another device, i.e. throu…

Apple needs to keep ports open for diagnostic purposes even on "portless" hardware.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#228
post #182

Earlier quoted context omitted.

On the latest iOS, on the latest/largest iPhone, this does not appear to be true any longer.

It does; five rapid clicks to the side button will trigger an alarm and require a passcode to unlock.

Unable to reproduce on iPhone 12 Pro Max on 14.4.

Re: Evidence that the FBI can hack into private Signal messages on a locked iPhone

#230

Universal encryption is a defense against blanket vacuuming of communications for later offline analysis. Its a defense against a massive parallel MITM attack against the world's communications infrastructure. Its not a defense against targeted attacks of individual devices.

The point of encryption and privacy software isn't to make it completely impossible to violate someone's privacy. We still have laws that most of us agree with and want to see them enforced. The point is to make it impossible to compromise everyone all at once and stream that data into a system designed to automate the manufacturing of consent. It has to cost something non negligible to violate someone's privacy, and…

Very nicely put. Thanks.
Post reply on HN