FBI's ability to legally access secure messaging app content and metadata [pdf]
11–20 of 474 posts
Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#12It says Telegram has no message content. Isn't telegram not E2EE by default, instead required explicit steps to make a conversation encrypted? Either way looks like Signal wins by a lot. The size of it spot is so small, it seems almost squeezed in. But only because they have nothing to share.
I don't know whether Telegram is E2EE by default (probably not.) When you do a call on telegram you are given a series of emoji and they are supposed to match what the person on the other side has, and that's supposed to indicate E2EE for that call.
Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#13It says Telegram has no message content. Isn't telegram not E2EE by default, instead required explicit steps to make a conversation encrypted? Either way looks like Signal wins by a lot. The size of it spot is so small, it seems almost squeezed in. But only because they have nothing to share.
Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#14Knowing how well guarded IOS is against app developers, I wonder what kind of zero-day would suddenly turn a message received in WhatsApp to full system access. I think NSO found a WhatsApp backdoor, not a zero-day bug.
Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#15What about regular text messages?
Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#16So if you have something to hide, don't use iCloud backup. And Whatsapp will give them the target's full contactbook (was to be expected), but also everyone that has the target in their contact list. That last one is quite far reaching.
Can you turn that off if you have icloud or do you need to not use icloud all together?
Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#17If it’s not in your physical possession, it’s not your computer. If it’s not your computer, then whoever administers the computer, or whoever [points a gun at/gives enough money to] the administrator of that system can access whatever you put on that system.
If a “cloud” or “service” is involved, then you can trivially use them to move or store data that you encrypted locally on your computer with your key that was generated and stored locally and never left your system. But subject to the limits above, the administrators of the other computers will still be able to see metadata like where the data came from and is going to. And they might be able to see your data too if you ever (even once, ask Ross Ulbrecht) failed to follow the basic encryption guidelines above.
You can make metadata access harder via VPNs and Tor, but you CANNOT make it impossible- in the worst case, maybe your adversary is controlling all the Tor nodes and has compromised the software.
Which leads me to my last point, if you did not write (or at least read) the code that you’re using to do all of the above, then you’re at the mercy of whoever wrote it.
And, if you try to follow perfect operational security, you will have a stressful and unpleasant life, as it’s really really hard.
Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#18So if you have something to hide, don't use iCloud backup. And Whatsapp will give them the target's full contactbook (was to be expected), but also everyone that has the target in their contact list. That last one is quite far reaching.
Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#19What about regular text messages?
Re: FBI's ability to legally access secure messaging app content and metadata [pdf]
#20LINE,telegram,threema and WeChat are not even american companies. Can't they just tell the FBI to suck a fat one when they ask for user data?
You don’t get to pick your jurisdiction and then operate globally. You’re obligated to follow the laws where you want to operate.