Live data from Hacker News

FBI's ability to legally access secure messaging app content and metadata [pdf]

propertyofthepeople.org

11–20 of 474 posts

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#12
post #9
post #6

It says Telegram has no message content. Isn't telegram not E2EE by default, instead required explicit steps to make a conversation encrypted? Either way looks like Signal wins by a lot. The size of it spot is so small, it seems almost squeezed in. But only because they have nothing to share.

I don't know whether Telegram is E2EE by default (probably not.) When you do a call on telegram you are given a series of emoji and they are supposed to match what the person on the other side has, and that's supposed to indicate E2EE for that call.

Verification in band seems pretty meaningless, approaching security theatre.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#13
post #6

It says Telegram has no message content. Isn't telegram not E2EE by default, instead required explicit steps to make a conversation encrypted? Either way looks like Signal wins by a lot. The size of it spot is so small, it seems almost squeezed in. But only because they have nothing to share.

That is correct. By default all messages sent over Telegram are stored permanently in their servers unencrypted.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#14
Well, who cares when all they need is to use something like Pegasus to obtain full access to your phone simply by sending you a WhatsApp message (without having you even open the message).

Knowing how well guarded IOS is against app developers, I wonder what kind of zero-day would suddenly turn a message received in WhatsApp to full system access. I think NSO found a WhatsApp backdoor, not a zero-day bug.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#16
post #4

So if you have something to hide, don't use iCloud backup. And Whatsapp will give them the target's full contactbook (was to be expected), but also everyone that has the target in their contact list. That last one is quite far reaching.

Can you turn that off if you have icloud or do you need to not use icloud all together?

[deleted]

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#17
This discussion is not very interesting from a security perspective. I tuned out at “cloud”.

If it’s not in your physical possession, it’s not your computer. If it’s not your computer, then whoever administers the computer, or whoever [points a gun at/gives enough money to] the administrator of that system can access whatever you put on that system.

If a “cloud” or “service” is involved, then you can trivially use them to move or store data that you encrypted locally on your computer with your key that was generated and stored locally and never left your system. But subject to the limits above, the administrators of the other computers will still be able to see metadata like where the data came from and is going to. And they might be able to see your data too if you ever (even once, ask Ross Ulbrecht) failed to follow the basic encryption guidelines above.

You can make metadata access harder via VPNs and Tor, but you CANNOT make it impossible- in the worst case, maybe your adversary is controlling all the Tor nodes and has compromised the software.

Which leads me to my last point, if you did not write (or at least read) the code that you’re using to do all of the above, then you’re at the mercy of whoever wrote it.

And, if you try to follow perfect operational security, you will have a stressful and unpleasant life, as it’s really really hard.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#18
post #4

So if you have something to hide, don't use iCloud backup. And Whatsapp will give them the target's full contactbook (was to be expected), but also everyone that has the target in their contact list. That last one is quite far reaching.

Has Apple made any public statements regarding iCloud's lack of privacy features. It takes the wind out of their privacy marketing that is effectively hurting ad tech but not truly protecting consumers from state-level actors with data access.

Re: FBI's ability to legally access secure messaging app content and metadata [pdf]

#20
post #11

LINE,telegram,threema and WeChat are not even american companies. Can't they just tell the FBI to suck a fat one when they ask for user data?

Not if they want to operate in the United States or have access to our banking system.

You don’t get to pick your jurisdiction and then operate globally. You’re obligated to follow the laws where you want to operate.

Post reply on HN