Live data from Hacker News

Grand jury subpoena for Signal user data, Central District of California

signal.org

191–200 of 226 posts

Re: Grand jury subpoena for Signal user data, Central District of California

#191
post #187

It's probably unwise to think prosecutors and federal agents are stupid. They were in the 1990s crypto wars, but not now. What we tend to perceive as 'stupid' is in reality, 'powerful.' They don't need to explain themselves, because they put the onus of compliance on you. Gaming out the subpoena, Signal does not have this user information because it does not exist, but it does have server locations, 3rd party service…

To Mark Zuckerberg: "So, how do you sustain a business model in which users don’t pay for your service?" To George Floyd witness: "So you had something called a mobile device right? And a mobile device is capable of taking pictures right? And you used the mobile device to use that capability right? And your eyes were able to see things besides the phone right?" No shit Sherlock, have you never used Facebook and seen…

Old prosecutor's/attorney's trick. Never ask a question you don't already know the answer to. You're there to tease out the record in your favor, and try to control the narrative through leading questions.

The legal system is not about truth. It's about corraling 12 fish out of water to your way of seeing things. Throw the judges/lawyers a curveball with something like jury nullification and see how quick things get nasty.

Re: Grand jury subpoena for Signal user data, Central District of California

#192
post #177

My fear with Signal being so giddy about what they don't have is that it will convince Congress to make a law forcing them to collect the data they don't have, the laws of math be damned. I worry that Congress with just make them liable if they are requested to produce location data and are unable to do so, for example.

As a Signal user it does not make me happy either that they seem to enjoy thwarting law enforcement for its own sake. I'm not a criminal. I just enjoy privacy and good software. I don't enjoy thumbing my nose at the justice department when they're just trying to do their job protecting citizens from criminals. Signal, just follow the law and quit acting so happy whenever your software helps a criminal get away with c…

The problem is prosecuters have a history of seeing just how much they can get away with (just like cops, except they have the power to shoot you in the face). Your attitude is a bad one, because "they're just trying to do their jobs" has been used for centuries to advocate for the government to take more and more freedom away from citizens because it "makes their policing powers easier". I'm sure the Stasi liked it that their police powers were quite ample, but it doesn't make it right.

Re: Grand jury subpoena for Signal user data, Central District of California

#193
post #182
post #177

Earlier quoted context omitted.

As a Signal user it does not make me happy either that they seem to enjoy thwarting law enforcement for its own sake. I'm not a criminal. I just enjoy privacy and good software. I don't enjoy thumbing my nose at the justice department when they're just trying to do their job protecting citizens from criminals. Signal, just follow the law and quit acting so happy whenever your software helps a criminal get away with c…

Speak for yourself. I am a criminal and I'm happy that Signal has my back. In fact I'd argue that anyone who is not a criminal is probably quite a boring and uninteresting person.

Most people break laws every day without even knowing it.

Re: Grand jury subpoena for Signal user data, Central District of California

#194
post #187

Earlier quoted context omitted.

To Mark Zuckerberg: "So, how do you sustain a business model in which users don’t pay for your service?" To George Floyd witness: "So you had something called a mobile device right? And a mobile device is capable of taking pictures right? And you used the mobile device to use that capability right? And your eyes were able to see things besides the phone right?" No shit Sherlock, have you never used Facebook and seen…

Old prosecutor's/attorney's trick. Never ask a question you don't already know the answer to. You're there to tease out the record in your favor, and try to control the narrative through leading questions. The legal system is not about truth. It's about corraling 12 fish out of water to your way of seeing things. Throw the judges/lawyers a curveball with something like jury nullification and see how quick things get…

If you know the answer, just say it. I don't want to pay $900/hour for someone to ask rhetorical questions.

Re: Grand jury subpoena for Signal user data, Central District of California

#195
post #152
post #71

Earlier quoted context omitted.

Anything that is in web browser (like e.g most uses of protonmail) offloads all security to the security of the TLS connection. Unless you also ensure proper certificate pining, if someone can get a court order for any accepted CA to give them a valid certificate for your domain you won't notice a thing while that someone gets your browser to run any code and e.g. dump keys, certificates or messages.

> if someone can get a court order for any accepted CA to give them a valid certificate for your domain you won't notice a thing Certificate transparency logs make it possible to notice. I'm not 100% sure, but I think all major browsers require certificates to be logged at this point; and there are several services that you can list your domain and get notified when a certificate is issued. You (or your users) may st…

> I think all major browsers require certificates to be logged at this point

None of the browsers require by policy that certificates be logged. What this means is that the existence of a certificate which wasn't logged is not by itself a misissuance. Whereas for example the Apple 398 day rule is a policy rule, so a certificate which breaks the rule not only won't work in Safari, but it is also a misissuance and your whole CA might get distrusted by Apple.

However, all the major browsers except Firefox require that certificates they are shown which purport to have been issued after a mandate are presented with SCTs. We'll discuss what that means below. For Chrome that mandate begins after 30 April 2018, which means it doesn't catch certificates issued in a small window of time when certificate lifetimes up to 39 months were still allowed at the start of 2018, the last of these certificates would expire at the end of next month, May 2021.

In practice no public CA was selling unlogged certificates intended for web servers by the point the mandate triggers, it would have been a needless business risk to sail so close to the wind, so chances are no certificates in this category exist today.

Signed Certificate Timestamps are issued by the log, they are like "proof of posting" when you send a letter. The log warrants that any certificates for which it has issued SCTs will appear within the Maximum Merge Delay (for public CT logs this is 24 hours).

That might seem like a long time, but it's a do-or-die promise. Logs which experience a problem making them unable to show a consistent log with the corresponding certificate within 24 hours are disqualified and you need to start over, because without such a rule obviously you can smuggle anything into an outage.

Google and Safari's policy (I don't know the Edge policy) dictates two or more SCTs, at least one to be from a log controlled by Google. So this gives Google the handy property that they don't need to trust any combination of third parties, you must show all certificates to Google itself.

Re: Grand jury subpoena for Signal user data, Central District of California

#196
post #194

Earlier quoted context omitted.

Old prosecutor's/attorney's trick. Never ask a question you don't already know the answer to. You're there to tease out the record in your favor, and try to control the narrative through leading questions. The legal system is not about truth. It's about corraling 12 fish out of water to your way of seeing things. Throw the judges/lawyers a curveball with something like jury nullification and see how quick things get…

If you know the answer, just say it. I don't want to pay $900/hour for someone to ask rhetorical questions.

Attorneys for parties ina case are not witnesses, can’t be cross-examined, and are not permitted to just introduce fact claims into evidence themselves. They have to ask questions of witnesses, who are the subject to cross examination.

There a very good reasons for it even if it isn’t maximally entertaining viewing.

Re: Grand jury subpoena for Signal user data, Central District of California

#197
post #178

While I generally support Signal's mission, let's not get too taken in by their own PR and its triumphal tone, however satisfying it may be to thumb one's nose at the powerful. (People tend to trust the PR they like and distrust PR they don't like - let's think critically about of all of it.) Based only on this post and the Cellebrite hack, Signal appears overconfident, taken with their own press clippings, and makin…

Several security teams do this. Project Zero and it's various researcher have been thumbing their noses at software companies for a long time. The Cellebrite hack is not a shocking thing, similar demonstrations have been done for other digital forensics, IDS/IPS systems, and others over the last 20 years (longer?). This notion that directly, and clearly calling out your adversaries deficiencies is unprofessional or a…

Project Zero tries to improve security for the public and in ways that directly or indirectly affect Google, as do many other hackers, by informing the public of risks and by pressuring developers to be more diligent and to fix specific vulnerabilities.

I don't see Signal's recent blog post as trying to pressure Cellebrite to improve their security. And the fact that other people do something isn't evidence of good judgment - other people can be stupid, and your circumstances are your own. Moxy doesn't work for possibly the most well-resourced security organization in the world (maybe outside the NSA), and he's not some independent hacker: he has a company, a product, and the privacy of millions of people that he has taken responsibility for - it's like having kids: you don't get to think of just yourself anymore, ever.

> asinine

At least you take your own advice.

Re: Grand jury subpoena for Signal user data, Central District of California

#198
post #194

Earlier quoted context omitted.

If you know the answer, just say it. I don't want to pay $900/hour for someone to ask rhetorical questions.

Attorneys for parties ina case are not witnesses, can’t be cross-examined, and are not permitted to just introduce fact claims into evidence themselves. They have to ask questions of witnesses, who are the subject to cross examination. There a very good reasons for it even if it isn’t maximally entertaining viewing.

> introduce fact claims

I'm sure everyone would agree that people have eyes and phones and that a phone can take pictures. Why is that a fact claim? Just show the pictures. And then ask real questions, like "what do you see" "oh look someone's knee on someone's neck". I hate inefficiency.

Re: Grand jury subpoena for Signal user data, Central District of California

#199

Earlier quoted context omitted.

Because a prosecutor calls up the IT crime lab and asks for the rundown. And since they have massive budgets, there actually is a well trained head of the IT crime lab who is perfectly capable of understanding and explaining (to a jury) how Signal works.

You’re very optimistic about the state of budgets, crime lab competence, etc

End to end encryption is not a complex thing to explain

Re: Grand jury subpoena for Signal user data, Central District of California

#200
post #173

Earlier quoted context omitted.

Signal seems secure from the outside, but is it? A judge won't simply take their word for it that they don't have the data, they'll make the order and see if anything turns up. What if there's a misconfigured logging server that has information that can be used to identify users? Well then that's now going to be given to the government and if Signal tries to turn it off they'll be liable for destruction of evidence.…

Judges taking their word for it is exactly what happens when you respond to a subpoena. That’s literally how it works.

No. If they don't find an excuse plausible (possibly due to the objections of the counterparty), they might order production of evidence to support it.

A judge could in theory respond with 'orly, hand over source code'. What the judge could not do is say 'ok, source code shows you're telling the truth, but you should change it to record the information the prosecutor wants.' Only the legislative branch could do that.

Post reply on HN