Live data from Hacker News

Grand jury subpoena for Signal user data, Central District of California

signal.org

31–40 of 226 posts

Re: Grand jury subpoena for Signal user data, Central District of California

#31
post #3

Let's see if they try to search the Signal servers for any evidence. And if there is really no information stored. Or if that will disrupt Signal services. The central, non-distributed architecture is always a big concern against Signal.

Surprisingly, the response from the Signal team hints that Signal is sometimes P2P. This is the first time I hear about this, what is it referring to exactly? I, like you, thought Signal was 100% centralized.

> [...] because the data is transmitted peer-to-peer or relayed through a third-party server [...]

Attachment A, Section 2C

Re: Grand jury subpoena for Signal user data, Central District of California

#32
post #14

For their first subpoena [1], they said: > It originally included a broad gag order that would have prevented us from publishing this notice, but the ACLU represented us in quickly and successfully securing our ability to publish the transcripts below. This subpoena says: > you are asked not to disclose the existence of nature of the subpoena But the post doesn't mention that at all. I wonder how much effort they had…

Does the phrase "you are asked" have a legal bearing though? is it something they can just choose to not follow, since they were not "told" or "instructed"?

Given that the following sentence says "If you nonetheless plan to disclose the existence or nature of the subpoena, please contact the Special Agent identified above first".

I suspect it might not. I don't know why this additional information wasn't quoted by the parent comment.

Re: Grand jury subpoena for Signal user data, Central District of California

#33
post #27

Earlier quoted context omitted.

Even if it's decentralized there's only one client and they can always push updates to male it send keys/messages back for targeted users. Smartphones in their current form cannot have secure messaging.

>Smartphones in their current form cannot have secure messaging. What about self-hosted matrix/element, used from the browser?

I think the parent poster wanted to highlight the auto update feature of phones.

Re: Grand jury subpoena for Signal user data, Central District of California

#34
post #3

Let's see if they try to search the Signal servers for any evidence. And if there is really no information stored. Or if that will disrupt Signal services. The central, non-distributed architecture is always a big concern against Signal.

Surprisingly, the response from the Signal team hints that Signal is sometimes P2P. This is the first time I hear about this, what is it referring to exactly? I, like you, thought Signal was 100% centralized. > [...] because the data is transmitted peer-to-peer or relayed through a third-party server [...] Attachment A, Section 2C

I believe that voice and video calls work using WebRTC, which is a P2P technology

Re: Grand jury subpoena for Signal user data, Central District of California

#35
post #17

Earlier quoted context omitted.

Matrix is not ready for non-technical people. Way too much stuff to consider as a user. It's similar to PGP a technology that will probably never go mainstream.

Is there? I'm definitely the kind of person who wants to set up my own server and bridges for it at some point, but when I tried Matrix for the first time last week I just created an account at matrix.org, installed a quite polished client and just started chatting.

The iOS client (Element) is garbage unless they fixed it in the last month. I suspect that’s what they’re referring to.

Re: Grand jury subpoena for Signal user data, Central District of California

#36
post #23

The subpoena is from Homeland Security Investigations at LAX airport. They deal specifically with crimes that involve international transport. So this is human trafficking, drug smuggling, money mules, etc. To be honest the rest of it is just standard "we have some phone numbers" boilerplate. Same thing was probably sent to Facebook, Twitter, etc. with the hopes that someone was dumb enough to login and check their m…

[deleted]

Re: Grand jury subpoena for Signal user data, Central District of California

#37
post #19

Earlier quoted context omitted.

Surprisingly, the subpoena does specify the file format, including the compression, rather precisely.

Not that surprising considering this overlaps with areas where lawyers may use every trick in the book to cooperate just enough as is necessary. Like when Lavabit was asked to provide an encryption key and they sent the 4096bit key printed out on multiple pages in a tiny font size.

I've read similar, over-precise phrasing in other documents, and there I got the impression that the specification was not based on understanding the tech, but simply copied from some other place where the request wasn't fucked up (as in your lavabit example).

Re: Grand jury subpoena for Signal user data, Central District of California

#38
> The subpoena requested a wide variety of information that fell into this nonexistent category, including the addresses of the users, their correspondence, and the name associated with each account.

And in other jurisdictions, only the correspondence would be inaccessible. Furthermore, there would be no need to contact Signal because you can get that information just from their phone number.

Just in case anyone is still wondering why there are users who still complain about Signal linking accounts to phone numbers.

Re: Grand jury subpoena for Signal user data, Central District of California

#39
post #34

Earlier quoted context omitted.

Surprisingly, the response from the Signal team hints that Signal is sometimes P2P. This is the first time I hear about this, what is it referring to exactly? I, like you, thought Signal was 100% centralized. > [...] because the data is transmitted peer-to-peer or relayed through a third-party server [...] Attachment A, Section 2C

I believe that voice and video calls work using WebRTC, which is a P2P technology

WebRTC (still) requires a centralized server in order to setup the connection (via STUN/TURN), so if so, Signal could be forced to turn over any logging they have of those setup requests.

Re: Grand jury subpoena for Signal user data, Central District of California

#40
post #27
post #3

Let's see if they try to search the Signal servers for any evidence. And if there is really no information stored. Or if that will disrupt Signal services. The central, non-distributed architecture is always a big concern against Signal.

Even if it's decentralized there's only one client and they can always push updates to male it send keys/messages back for targeted users. Smartphones in their current form cannot have secure messaging.

Signal can stop you from using the service until you update, but they can't force you to update their app.
Post reply on HN