Live data from Hacker News

Grand jury subpoena for Signal user data, Central District of California

signal.org

11–20 of 226 posts

Re: Grand jury subpoena for Signal user data, Central District of California

#11
I am not a lawyer.

The lawyers at DOJ know what they are doing (notwithstanding the history or fact that signal will respond with little information): The subpoena has a request for interstate wire to help them quash future motions to dismiss on jurisdictional grounds.

Whatever statute they're looking to charge will have an element of federal jurisdiction attached and interstate wire works great even if there are other ways. It's easy to ask, so they'll ask for it all.

Re: Grand jury subpoena for Signal user data, Central District of California

#12

So as I type this, Signal have two stories in top-10 on HN: more coverage of Signal's Cellebrite Hack, and this. Are they connected? Signal gets this subpoena on the 29th March, and the reply by ACLU is on the 12th April. Signal's founder and CEO, Moxie Marlinspike, hacked Cellebrite and the story surfaced this week. Was it retaliation? Was it just because the subpoena made him wonder? Or is there something else caus…

The reason they've mentioned "first half" of 2016 is because this isn't first such subpoena. See: https://signal.org/bigbrother/eastern-virginia-grand-jury/

Doubtful there's any connection between the two.

Re: Grand jury subpoena for Signal user data, Central District of California

#13

So as I type this, Signal have two stories in top-10 on HN: more coverage of Signal's Cellebrite Hack, and this. Are they connected? Signal gets this subpoena on the 29th March, and the reply by ACLU is on the 12th April. Signal's founder and CEO, Moxie Marlinspike, hacked Cellebrite and the story surfaced this week. Was it retaliation? Was it just because the subpoena made him wonder? Or is there something else caus…

Cellebrite made a splash some time ago that their tools can extract Signal messages from the (unlocked?) devices. The claim was " Cellebrite can now break into Signal, an encrypted app considered safe from external snooping, it claimed." [1] And I guess that did not sit too well with Moxie :)

[1] - https://securityboulevard.com/2020/12/signal-app-crypto-crac...

Re: Grand jury subpoena for Signal user data, Central District of California

#14
For their first subpoena [1], they said:

> It originally included a broad gag order that would have prevented us from publishing this notice, but the ACLU represented us in quickly and successfully securing our ability to publish the transcripts below.

This subpoena says:

> you are asked not to disclose the existence of nature of the subpoena

But the post doesn't mention that at all. I wonder how much effort they had to spend, if any, to be able to publish this this time.

[1] https://signal.org/bigbrother/eastern-virginia-grand-jury/

Re: Grand jury subpoena for Signal user data, Central District of California

#15
post #9
post #3

Let's see if they try to search the Signal servers for any evidence. And if there is really no information stored. Or if that will disrupt Signal services. The central, non-distributed architecture is always a big concern against Signal.

Agreed. I really wish they would go decentralised. If they did, I'd order up my 1gbit/1gbit dedicated link at the office and offer it up immediately.

If you want something decentralised what's wrong with doing the same with Tor and/or Matrix?

Re: Grand jury subpoena for Signal user data, Central District of California

#16
post #2

Page 8 of that subpoena says the document files produced must have the extension "*.TIF". (note asterisk) I wonder how they'd like it if you sent them files literally named FILE001.PAGE001.*.TIF (the rest of the specified file format structure notwithstanding) It's very important to follow the instructions exactly when you are legally compelled to do something!

It’s interesting how the government gets to demand the evidence in a very specific format, thereby offloading the work the government should be doing onto someone else, apparently without recompense.

Re: Grand jury subpoena for Signal user data, Central District of California

#17
post #15
post #9

Earlier quoted context omitted.

Agreed. I really wish they would go decentralised. If they did, I'd order up my 1gbit/1gbit dedicated link at the office and offer it up immediately.

If you want something decentralised what's wrong with doing the same with Tor and/or Matrix?

Matrix is not ready for non-technical people. Way too much stuff to consider as a user. It's similar to PGP a technology that will probably never go mainstream.

Re: Grand jury subpoena for Signal user data, Central District of California

#18
OT and tinfoil hat on; there was a strange event last week with users of Signal on the Telia ISP.[1]

For about 24 hours no messages could be sent, resulting in a 401 unauthorized error from the server side.

Telia is the former state-owned Swedish ISP that is now only half state-owned I believe.

They have a bad rep already for sending out extortion letters to torrent users and are almost assumed to be monitoring all user traffic for the police.

No explanation of the event has been provided by anyone. Users have done some basic troubleshooting but couldn't really establish much. I personally would love to see what those 401 errors looked like on the Signal server side. What exactly were these clients sending that was unauthorized on the server side? I guess we'll never know, hopefully it wasn't even stored.

1. https://github.com/signalapp/Signal-Desktop/issues/5202

Re: Grand jury subpoena for Signal user data, Central District of California

#19
post #5
post #2

Page 8 of that subpoena says the document files produced must have the extension "*.TIF". (note asterisk) I wonder how they'd like it if you sent them files literally named FILE001.PAGE001.*.TIF (the rest of the specified file format structure notwithstanding) It's very important to follow the instructions exactly when you are legally compelled to do something!

Q: "Why did you send us BPGs[0] named .TIF?" A: "Because you specified an extension, not a file format." [0] https://bellard.org/bpg/

Surprisingly, the subpoena does specify the file format, including the compression, rather precisely.

Re: Grand jury subpoena for Signal user data, Central District of California

#20

OT and tinfoil hat on; there was a strange event last week with users of Signal on the Telia ISP.[1] For about 24 hours no messages could be sent, resulting in a 401 unauthorized error from the server side. Telia is the former state-owned Swedish ISP that is now only half state-owned I believe. They have a bad rep already for sending out extortion letters to torrent users and are almost assumed to be monitoring all u…

> They have a bad rep already for sending out extortion letters to torrent users

That's almost never the ISPs doing, they are being strong armed by IP owners.

Post reply on HN