Live data from Hacker News

Grand jury subpoena for Signal user data, Central District of California

signal.org

21–30 of 226 posts

Re: Grand jury subpoena for Signal user data, Central District of California

#22
post #14

For their first subpoena [1], they said: > It originally included a broad gag order that would have prevented us from publishing this notice, but the ACLU represented us in quickly and successfully securing our ability to publish the transcripts below. This subpoena says: > you are asked not to disclose the existence of nature of the subpoena But the post doesn't mention that at all. I wonder how much effort they had…

Does the phrase "you are asked" have a legal bearing though? is it something they can just choose to not follow, since they were not "told" or "instructed"?

Re: Grand jury subpoena for Signal user data, Central District of California

#23
The subpoena is from Homeland Security Investigations at LAX airport.

They deal specifically with crimes that involve international transport. So this is human trafficking, drug smuggling, money mules, etc.

To be honest the rest of it is just standard "we have some phone numbers" boilerplate. Same thing was probably sent to Facebook, Twitter, etc. with the hopes that someone was dumb enough to login and check their messages from a burner phone.

Edit: Rereading it, this is a grand jury. They likely already know the who, what, why, and how. Signal's response will go to support other evidence that they may have recovered from cell phones or cell network. Grand juries historically result in a 95%+ chance of indictment so this isn't a fishing expedition.

Re: Grand jury subpoena for Signal user data, Central District of California

#24
post #20

OT and tinfoil hat on; there was a strange event last week with users of Signal on the Telia ISP.[1] For about 24 hours no messages could be sent, resulting in a 401 unauthorized error from the server side. Telia is the former state-owned Swedish ISP that is now only half state-owned I believe. They have a bad rep already for sending out extortion letters to torrent users and are almost assumed to be monitoring all u…

> They have a bad rep already for sending out extortion letters to torrent users That's almost never the ISPs doing, they are being strong armed by IP owners.

Sure, but some ISPs get strong-armed while others get... weak-armed. (And that's being generous to many of them.)

Re: Grand jury subpoena for Signal user data, Central District of California

#25
post #17
post #15

Earlier quoted context omitted.

If you want something decentralised what's wrong with doing the same with Tor and/or Matrix?

Matrix is not ready for non-technical people. Way too much stuff to consider as a user. It's similar to PGP a technology that will probably never go mainstream.

Is there? I'm definitely the kind of person who wants to set up my own server and bridges for it at some point, but when I tried Matrix for the first time last week I just created an account at matrix.org, installed a quite polished client and just started chatting.

Re: Grand jury subpoena for Signal user data, Central District of California

#26
post #14

For their first subpoena [1], they said: > It originally included a broad gag order that would have prevented us from publishing this notice, but the ACLU represented us in quickly and successfully securing our ability to publish the transcripts below. This subpoena says: > you are asked not to disclose the existence of nature of the subpoena But the post doesn't mention that at all. I wonder how much effort they had…

Does the phrase "you are asked" have a legal bearing though? is it something they can just choose to not follow, since they were not "told" or "instructed"?

Given that the subpoena itself contains language such as "YOU ARE COMMANDED" (sic), probably not, but I imagine Moxie asked the ACLU lawyers before making it public.

Re: Grand jury subpoena for Signal user data, Central District of California

#27
post #3

Let's see if they try to search the Signal servers for any evidence. And if there is really no information stored. Or if that will disrupt Signal services. The central, non-distributed architecture is always a big concern against Signal.

Even if it's decentralized there's only one client and they can always push updates to male it send keys/messages back for targeted users.

Smartphones in their current form cannot have secure messaging.

Re: Grand jury subpoena for Signal user data, Central District of California

#28
post #19
post #5

Earlier quoted context omitted.

Q: "Why did you send us BPGs[0] named .TIF?" A: "Because you specified an extension, not a file format." [0] https://bellard.org/bpg/

Surprisingly, the subpoena does specify the file format, including the compression, rather precisely.

Not that surprising considering this overlaps with areas where lawyers may use every trick in the book to cooperate just enough as is necessary. Like when Lavabit was asked to provide an encryption key and they sent the 4096bit key printed out on multiple pages in a tiny font size.

Re: Grand jury subpoena for Signal user data, Central District of California

#29
post #9
post #3

Let's see if they try to search the Signal servers for any evidence. And if there is really no information stored. Or if that will disrupt Signal services. The central, non-distributed architecture is always a big concern against Signal.

Agreed. I really wish they would go decentralised. If they did, I'd order up my 1gbit/1gbit dedicated link at the office and offer it up immediately.

I used to think the same, but I changed my mind after this talk : https://www.youtube.com/watch?v=Nj3YFprqAr8

There is a lot of very good point in this talk by Moxie, it's a bit long, but worth it.

Re: Grand jury subpoena for Signal user data, Central District of California

#30
post #27
post #3

Let's see if they try to search the Signal servers for any evidence. And if there is really no information stored. Or if that will disrupt Signal services. The central, non-distributed architecture is always a big concern against Signal.

Even if it's decentralized there's only one client and they can always push updates to male it send keys/messages back for targeted users. Smartphones in their current form cannot have secure messaging.

>Smartphones in their current form cannot have secure messaging.

What about self-hosted matrix/element, used from the browser?

Post reply on HN